Tuesday, November 12, 2024
HomeCVE/vulnerabilityLazarus Hacker Group Exploited Microsoft Windows Zero-day

Lazarus Hacker Group Exploited Microsoft Windows Zero-day

Published on

Malware protection

The notorious Lazarus hacker group has been identified as exploiting a zero-day vulnerability in Microsoft Windows, specifically targeting the Windows Ancillary Function Driver for WinSock (AFD.sys).

This vulnerability, cataloged as CVE-2024-38193, was discovered by researchers Luigino Camastra and Milanek in early June 2024.

The flaw allowed the group to gain unauthorized access to sensitive system areas, posing a significant threat to users worldwide.

- Advertisement - SIEM as a Service

CVE-2024-38193: A Critical Security Vulnerability

The CVE-2024-38193 vulnerability is classified as an “Elevation of Privilege” flaw. It allowed attackers to bypass normal security restrictions and access sensitive system areas that are typically off-limits to most users and administrators.

This type of attack is sophisticated and resourceful. It is estimated to be worth several hundred thousand dollars on the black market.

The vulnerability was exploited using a specialized malware known as “Fudmodule,” which effectively concealed the hackers’ activities from security software.

Free Webinar on Detecting & Blocking Supply Chain Attack -> Book your Spot

The Lazarus group targeted individuals in sensitive fields, such as cryptocurrency engineering and aerospace, aiming to infiltrate their employers’ networks and steal cryptocurrencies to fund their operations.

Microsoft Responds with a Critical Patch

In response to this alarming threat, Microsoft has swiftly issued a patch to address the critical vulnerability.

The company’s proactive efforts were bolstered by the Gen cybersecurity team, which alerted Microsoft to the issue and provided detailed example code that helped pinpoint and resolve the flaw effectively.

This rapid action has safeguarded all vulnerable Windows devices from potential attacks. All Windows users must update their systems promptly and remain vigilant against potential threats for continued protection.

Gen’s commitment to digital freedom extends beyond protecting its customers; it involves safeguarding the entire digital ecosystem.

Through rigorous research and deep visibility into emerging threats, their cybersecurity team was able to uncover this critical vulnerability and bring it to light before it could cause widespread harm.

By sharing this information with Microsoft, Gen has protected millions of Windows users worldwide and reaffirmed its dedication to creating a safer digital future for all.

This effort is a testament to Gen’s mission of empowering and protecting people everywhere, ensuring everyone can navigate the digital world confidently and securely.

The vulnerability is associated with the weakness CWE-416: Use After Free, with a CVSS score of 7.8/7.2, indicating its high severity.

Microsoft, the assigning CNA, has classified the maximum severity of this vulnerability as “Important.”

As the digital landscape continues to evolve, this incident underscores the importance of collaboration between cybersecurity experts and technology companies to protect users from sophisticated cyber threats.

Are you from SOC and DFIR Teams? Analyse Malware Incidents & get live Access with ANY.RUN -> Get 14 Days Free Access

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

10 Best DNS Management Tools – 2025

Best DNS Management Tools play a crucial role in efficiently managing domain names and...

Sweet Security Announces Availability of its Cloud Native Detection & Response Platform on the AWS Marketplace

Customers can now easily integrate Sweet’s runtime detection and response platform into their AWS...

Researchers Detailed Credential Abuse Cycle

Cybercriminals exploit leaked credentials, obtained through various means, to compromise systems and data, enabling...

New Android Malware SpyAgent Taking Screenshots Of User’s Devices

SpyAgent, a newly discovered Android malware, leverages OCR technology to extract cryptocurrency recovery phrases...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Researchers Detailed Credential Abuse Cycle

Cybercriminals exploit leaked credentials, obtained through various means, to compromise systems and data, enabling...

New Android Malware SpyAgent Taking Screenshots Of User’s Devices

SpyAgent, a newly discovered Android malware, leverages OCR technology to extract cryptocurrency recovery phrases...

Tor Network Suffers IP Spoofing Attack Via Non-Exit Relays

In late October 2024, a coordinated IP spoofing attack targeted the Tor network, prompting...