Avast Software¤Ï2·î28Æü(Êƹñ»þ´Ö)¡¢¡ÖLazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day - Avast Threat Labs¡×¤Ë¤ª¤¤¤Æ¡¢ËÌÄ«Á¯¤Ë´Ø·¸¤·¤Æ¤¤¤ë¤È¤ß¤é¤ì¤ë¶¼°Ò¥°¥ë¡¼¥×¡ÖLazarus Group¡×¤¬Windowsɸ½à¥É¥é¥¤¥Ð¡¼¤Î¡Öappid.sys(¥¢¥×¥ê¥±¡¼¥·¥ç¥óID¥µ¡¼¥Ó¥¹)¡×¤Ë¸ºß¤¹¤ë¥¼¥í¥Ç¥¤¤ÎÀȼåÀ­¤ò°­ÍѤ·¤Æ¤¤¤ë¤³¤È¤òȯ¸«¤·¤¿¤È¤·¤Æ¡¢Ãí°Õ¤ò¸Æ¤Ó³Ý¤±¤¿¡£

Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day - Avast Threat Labs

¡ûWindows¤¬Êú¤¨¤ë¥¼¥í¥Ç¥¤ÀȼåÀ­¤È¤Ï

ȯ¸«¤µ¤ì¤¿¥¼¥í¥Ç¥¤¤ÎÀȼåÀ­¤Ï¡ÖCVE-2024-21338¡×¤È¤·¤ÆÄÉÀפµ¤ì¤Æ¤ª¤ê¡¢Microsoft¤Ï2·î13Æü(Êƹñ»þ´Ö)¤Ë½¤Àµ¥Ñ¥Ã¥Á¡ÖCVE-2024-21338 - Security Update Guide - Microsoft - Windows Kernel Elevation of Privilege Vulnerability¡×¤ò¸ø³«¤·¤Æ¤¤¤ë¡£

Avast Software¤Ë¤è¤ë¤È¡¢¤³¤ÎÀȼåÀ­¤Ïappid.sys¤ÎIOCTL¥Ç¥£¥¹¥Ñ¥Ã¥Á¥ã¡¼Æâ¤Ë¸ºß¤¹¤ë¤È¤¤¤¦¡£¤³¤ÎIOCTL¥Ç¥£¥¹¥Ñ¥Ã¥Á¥ã¡¼Æâ¤Ë¤Ï2¤Ä¤Î¥«¡¼¥Í¥ë´Ø¿ô¥Ý¥¤¥ó¥¿¤òÆþÎϤȤ·¤Æ¼õ¤±¼è¤ë½èÍý¤¬Â¸ºß¤¹¤ë¡£Ä̾¥«¡¼¥Í¥ë´Ø¿ô¥Ý¥¤¥ó¥¿¤òÅϤ»¤ë¥×¥í¥»¥¹¤Ï¥«¡¼¥Í¥ë¥â¡¼¥É¤ÇÆ°ºî¤·¤Æ¤¤¤ë¥×¥í¥»¥¹¤À¤±¤Ç¤¢¤ê¡¢Avast Software¤â¾¤ÎAppLocker¥É¥é¥¤¥Ð¡¼¤«¤é¸Æ¤Ó½Ð¤µ¤ì¤Æ¤¤¤ë¤³¤È¤ò³Îǧ¤·¤Æ¤¤¤ë¡£¤·¤«¤·¤Ê¤¬¤é¡¢¤³¤ÎIOCTL¤Ï¥æ¡¼¥¶¡¼¶õ´Ö¤«¤é¥¢¥¯¥»¥¹²Äǽ¤Ê¤Þ¤Þ¤À¤Ã¤¿¤È¤¤¤¦¡£

¤Ä¤Þ¤ê¡¢¤³¤ÎÀȼåÀ­¤ò°­ÍѤ¹¤ë¤³¤È¤Ç¡¢¥æ¡¼¥¶¡¼¶õ´Ö¤«¤é¥«¡¼¥Í¥ë¤ò¤À¤Þ¤·¤ÆǤ°Õ¤Î¥Ý¥¤¥ó¥¿¡¼¤ò¸Æ¤Ó½Ð¤¹¤³¤È¤¬²Äǽ¤Ê¾õÂ֤ˤ¢¤Ã¤¿¡£¤Þ¤¿¡¢¥³¡¼¥ë¥Ð¥Ã¥¯´Ø¿ô¤ËÅϤ¹ºÇ½é¤Î°ú¿ô¤«¤é»²¾È¤µ¤ì¤ë¥Ç¡¼¥¿¤âÉôʬŪ¤ËÀ©¸æ²Äǽ¤À¤Ã¤¿¤È¤¤¤¦¡£

¤½¤Î¤¿¤á¡¢¹¶·â¼Ô¤Ï°ú¿ô¤ò¹âÅÙ¤ËÀ©¸æ¤·¤ÆÀȼåÀ­¤ò°­ÍѤ¹¤ë¤³¤È¤ÇǤ°Õ¤Î¥«¡¼¥Í¥ë´Ø¿ô¤ò¸Æ¤Ó½Ð¤»¤¿¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£¤Ê¤ª¡¢¤¹¤Ù¤Æ¤Î¥æ¡¼¥¶¡¼¤¬¤³¤ÎÀȼåÀ­¤ò°­ÍѤǤ­¤ë¤ï¤±¤Ç¤Ï¤Ê¤¯¡¢¥í¡¼¥«¥ë¥µ¡¼¥Ó¥¹¥¢¥«¥¦¥ó¥È¤òɬÍפȤ¹¤ë¡£

¡ûÀȼåÀ­¤Î±Æ¶Á¤ÈÂкö

Lazarus Group¤ÏFudModule¥ë¡¼¥È¥­¥Ã¥È¤ò·Ñ³¤·¤Æ³«È¯¤·¤Æ¤¤¤ë¤È¤ß¤é¤ì¡¢º£²ó³Îǧ¤µ¤ì¤¿ºÇ¿·¤ÎFudModule¥ë¡¼¥È¥­¥Ã¥È¤Ë¤Ï¤³¤ÎÀȼåÀ­¤Î°­ÍѤ¬ÁȤ߹þ¤Þ¤ì¤Æ¤¤¤ë¤È¤¤¤¦¡£¤µ¤é¤Ë¡¢¥»¥­¥å¥ê¥Æ¥£¥½¥ê¥å¡¼¥·¥ç¥ó¤ÎAhnLab V3 Endpoint Security¡¢Windows Defender¡¢CrowdStrike Falcon¡¢HitmanPro¤ò̵¸ú¤Ë¤¹¤ëµ¡Ç½¤ò»ý¤Á¡¢¹âÅ٤ʥ¹¥Æ¥ë¥¹À­¤È±Ê³²½¤ò¼Â¸½¤·¤Æ¤¤¤ë¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£

¤³¤Î¹¶·â¤ò²óÈò¤¹¤ë¤¿¤á¤Ë¡¢Windows¥æ¡¼¥¶¡¼¤Ï±Æ¶Á¤ò³Îǧ¤·¤ÆºÇ¿·¤Î¥Ñ¥Ã¥Á¤òŬÍѤ¹¤ë¤³¤È¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¡£¤Þ¤¿¡¢Avast Software¤ÏºÇ¿·¤ÎFudModule¥ë¡¼¥È¥­¥Ã¥È¤ò¸¡½Ð¤¹¤ë¤¿¤á¤ÎYara¥ë¡¼¥ë¤ò¡Öioc/FudModule at master · avast/ioc · GitHub¡×¤Ë¤Æ¸ø³«¤·¤Æ¤ª¤ê¡¢É¬Íפ˱þ¤¸¤Æ³èÍѤ¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£