Lazarus Group Exploits Windows Zero-Day
TL;DR. North Korean Lazarus Group exploited a Windows zero-day vulnerability to gain SYSTEM access and deploy a backdoor. - The advanced persistent threat group used the vulnerability for privilege escalation on compromised systems. - The attack allowed the deployment of a new remote access Trojan for persistent control. - Organizations should apply patches promptly and enhance endpoint detection capabilities.
- Lazarus Group (aka APT38, Hidden Cobra) exploited a Windows zero-day.
- The exploit granted SYSTEM-level privileges, bypassing security measures.
- A new backdoor, known as 'LightlessDoor', was deployed post-exploitation.
Sources
- Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor — thehackernews.com
- securityweek.com — securityweek.com