FudModule is a Windows rootkit associated with the North Korea-linked Lazarus Group and used to conceal malicious activity by interfering with endpoint protection, security telemetry, and forensic evidence collection. Observed since at least 2021, it includes user-mode DLL implementations that obtain kernel-memory access and manipulate Windows kernel structures rather than relying on a conventional malicious kernel driver. Campaigns deploying FudModule have targeted cryptocurrency engineering, aerospace, defense, and other industries; Citrine Sleet has also deployed it through a Chromium exploit chain.
Early variants used Bring Your Own Vulnerable Driver techniques involving legitimately signed Dell and ENE Technology drivers, including exploitation of CVE-2021-21551. Subsequent versions exploited built-in Windows drivers through CVE-2024-21338 and CVE-2024-38193. Its security-suppression mechanisms include removing registry and object callbacks, disabling process, thread, and image-load notifications, altering file-system minifilters, manipulating Event Tracing for Windows registration handles, and preventing new prefetch traces. Some variants use debugger checks, version-specific kernel offsets, victim validation, and VMProtect packing to restrict execution and hinder analysis.
FudModule v3.0 added crash-dump suppression and shellcode injection into legitimate Windows processes, using kernel-memory manipulation to bypass Protected Process Light protections and stage an associated payload. Version 3.1, deployed in Operation Dream Job recruitment-lure campaigns, incorporates exploitation of CVE-2026-68820 for SYSTEM privileges and adds Windows Smart App Control tampering. It also suppresses telemetry callbacks, minifilters, kernel logging, and numerous ETW providers. These recruitment-themed intrusion chains use spear-phishing, malicious archives, and DLL sideloading to establish execution before deploying FudModule through MISTPEN alongside other Lazarus malware, including ForestTiger.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In early June, researchers discovered that the Lazarus group was exploiting a security flaw in Windows' AFD.sys driver to access sensitive system areas. The attackers also used Fudmodule malware to hide their activities from security software.
The malware is a sophisticated, previously undocumented user-mode module that uses the BYOVD technique and leverages the CVE-2021-21551 vulnerability in a legitimate, signed Dell driver. After gaining write access to kernel memory, the module’s global goal is to blind security solutions and monitoring tools.
On August 19, 2024, Microsoft identified a North Korean threat actor exploiting a Chromium remote-code-execution (RCE) zero-day vulnerability ( CVE-2024-7971 )... Microsoft noted that Citrine Sleet used Chromium exploit to deploy a FudModule rootkit. | In early June, we discovered a sample that was exploiting a new zero-day vulnerability within Winsock driver (CVE-2024-38193) to achieve local privilege escalation to deploy a new version of FudModule rootkit.
The RCE vulnerability was used to deploy a shellcode containing another exploit ( CVE-2024-38106 ) that was used to escape Chromium’s sandbox and deploy the downloaded FudModule rootkit into the memory. | In early June, we discovered a sample that was exploiting a new zero-day vulnerability within Winsock driver (CVE-2024-38193) to achieve local privilege escalation to deploy a new version of FudModule rootkit.
Previous versions of FudModule (v2.0) were delivered by Kaolin RAT, utilizing another zero-day exploit ( CVE-2024-21338 ) to gain read/write access to the kernel memory. | In early June, we discovered a sample that was exploiting a new zero-day vulnerability within Winsock driver (CVE-2024-38193) to achieve local privilege escalation to deploy a new version of FudModule rootkit.
This exploit enables the attackers to deploy a rootkit known as FudModule v3.1, which disables logging systems, suppresses security software and, in the newest version, also disrupts Smart App Control, Check Point said.
Attackers deployed MISTPEN, Troy RAT, ForestTiger, and FudModule, including the exploitation of the CVE-2026-68820 zero-day in Windows AFD.sys for local privilege escalation and SYSTEM-level access.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We also discovered that they used a special type of malware called Fudmodule to hide their activities from security software.
“Microsoft published a blogpost, describing Citrine Sleet using a zero-day Chrome exploit to launch an evasive rootkit called FudModule.”
The 2022 emergence of FudModule represents a significant development for LABYRINTH CHOLLIMA’s malware capabilities. FudModule employs direct kernel manipulation for stealth and has leveraged zero-day exploits in vulnerable drivers, Chrome, and Windows.
The 2022 introduction of Fudmodule advanced capabilities through direct kernel manipulation and zero-day exploitation in vulnerable drivers, Chrome, and Windows.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Operation Dream Job campaign targeting the defense, aerospace, and aviation sectors through spear-phishing, job-offer lures, impersonation websites, SEO poisoning, and trojanized PDF viewers.
Operation Dream Job campaign targeting the defense, aerospace, and aviation sectors through spear-phishing, job-offer lures, impersonation websites, SEO poisoning, and trojanized PDF viewers.
The process involves two consecutive shellcode injections into different processes: one into services.exe and the other into msiexec.exe.
they employed the Bring Your Own Vulnerable Driver (BYOVD) technique, a well-known method where attackers load a legitimate, signed, and vulnerable kernel driver to bypass the Driver Signature Enforcement (DSE) policy. | we discovered a sample that was exploiting a new zero-day vulnerability within Winsock driver ( CVE-2024-38193 ) to achieve local privilege escalation to deploy a new version of FudModule rootkit.
kernel szintű rootkitet (FudModule) telepítenek, és hosszú távú hozzáférést létesítenek a kompromittált rendszereken
...through spear-phishing, job-offer lures, impersonation websites, SEO poisoning, and trojanized PDF viewers.
The process involves two consecutive shellcode injections into different processes: one into services.exe and the other into msiexec.exe.
They described 7 techniques used to disarm security solutions and monitoring tools... Disable process, thread and image kernel callbacks Disabling all monitoring and antivirus file system minifilters Disable network traffic filtering ... Disable monitoring of MsMpEng.exe process
80 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus rootkit deployed after kernel privilege escalation. It disables logging, suppresses security tools, and in the latest version interferes with Smart App Control.
Kernel-level rootkit deployed by Lazarus after exploiting CVE-2026-68820 to gain elevated privileges on compromised systems.
Kernel-level rootkit deployed after exploitation of a Windows local privilege escalation vulnerability to gain SYSTEM privileges, evade endpoint protections, and maintain long-term stealthy access.
A Lazarus kernel-mode rootkit used post-exploitation; version 3.1 can tamper with Windows Smart App Control to bypass software verification.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.