Hackers Exploiting Dell Driver Vulnerability to Deploy Rootkit on Targeted Computers

Home/Exploitation, Internet Security, Security Advisory, Security Update, Tips, vulnerability/Hackers Exploiting Dell Driver Vulnerability to Deploy Rootkit on Targeted Computers

Hackers Exploiting Dell Driver Vulnerability to Deploy Rootkit on Targeted Computers

The North Korea-backed Lazarus Team has been observed deploying a Windows rootkit by taking gain of an exploit in a Dell firmware driver, highlighting new tactics adopted by the state-sponsored adversary.

The EU-based targets of this campaign were emailed fake job offers, this time for Amazon, a typical and common social engineering trick employed by the hackers in 2022.

 The spear-phishing campaign unfolded in the autumn of 2021, and the confirmed targets, an aerospace expert in the Netherlands and a political journalist in Belgium, were emailed fake job offers at Amazon. ESET reports that among the tools deployed in this campaign, the most interesting is a new FudModule rootkit that abuses a BYOVD (Bring Your Own Vulnerable Driver) technique to exploit a vulnerability in a Dell hardware driver for the first time.

But what is actually noteworthy about the 2021 attacks was a rootkit module that exploited a Dell driver flaw to obtain the capability to go through and publish kernel memory. The issue, tracked as CVE-2021-21551, relates to a set of critical privilege escalation vulnerabilities in dbutil_2_3.sys.

“[This] signifies the initial recorded abuse of the CVE‑2021‑21551 vulnerability,” Kálnai pointed out. “This device, in mix with the vulnerability, disables the monitoring of all security alternatives on compromised equipment.”

Named FudModule, the earlier undocumented malware achieves its ambitions by means of multiple techniques “either not regarded prior to or familiar only to specialised security researchers and (anti-)cheat builders,” according to ESET.

“The attackers then utilised their kernel memory publish accessibility to disable 7 mechanisms the Windows working procedure gives to watch its actions, like registry, file procedure, course of action generation, party tracing, and so on., basically blinding security answers in a really generic and strong way,” Kálnai reported. “Definitely this expected deep research, advancement, and screening skills.”

This is not the first time the danger actor has resorted to using a susceptible driver to mount its rootkit attacks. Just previous thirty day period, AhnLab’s ASEC in-depth the exploitation of a authentic driver recognised as “ene.sys” to disarm security computer software installed in the equipment.

The results are a demonstration of the Lazarus Group’s tenacity and skill to innovate and shift its practices as necessary more than the years regardless of powerful scrutiny of the collective’s functions from both legislation enforcement and the broader study community.

SHA-1Filename
296D882CB926070F6E43C99B9E1683497B6F17C4FudModule.dll
001386CBBC258C3FCC64145C74212A024EAA6657C:\PublicCache\msdxm.ocx
569234EDFB631B4F99656529EC21067A4C933969colorui.dll
735B7E9DFA7AF03B751075FD6D3DE45FBF0330A2N/A
4AA48160B0DB2F10C7920349E3DCCE01CCE23FE3N/A
C71C19DBB5F40DBB9A721DC05D4F9860590A5762Adobe.tmp
97DAAB7B422210AB256824D9759C0DBA319CA468credui.dll
FD6D0080D27929C803A91F268B719F725396FE79N/A
83CF7D8EF1A241001C599B9BCC8940E089B613FBN/A
C948AE14761095E4D76B55D9DE86412258BE7AFDDBUtil_2_3.sys

By | 2022-10-17T16:33:10+05:30 October 3rd, 2022|Exploitation, Internet Security, Security Advisory, Security Update, Tips, vulnerability|

About the Author:

FirstHackersNews- Identifies Security

Leave A Comment

Subscribe to our newsletter to receive security tips everday!