Skip to content

Malware

FudModule

aka LIGHTSHOW

FudModule is a user-mode DLL that gets the ability to read and write arbitrary kernel memory via the BYOVD technique.

FudModule, also known as LIGHTSHOW, is a Windows malware family operated by Lazarus Group.

Background

FudModule is a user-mode DLL that gains arbitrary kernel memory read/write capability through the BYOVD technique. Its primary purpose is to disable Windows system-monitoring mechanisms by altering kernel variables and stripping out kernel callbacks. These manipulations are likely to undermine a range of security products, including EDRs, firewalls, antimalware, and even digital forensics tooling.


Source: Malpedia (Fraunhofer FKIE).