Skip to content

Malware

FudModule

aka LIGHTSHOW

FudModule is a user-mode DLL that gets the ability to read and write arbitrary kernel memory via the BYOVD technique.

FudModule is a user-mode DLL that gets the ability to read and write arbitrary kernel memory via the BYOVD technique. Its main goal is to turn off Windows system monitoring features, which is done by modifying kernel variables and removing kernel callbacks. Its actions may very likely affect various types of security products, e.g. EDRs, firewalls, antimalware and even digital forensics tools.


Family metadata imported from Malpedia (Fraunhofer FKIE).