Avast’s security analysts have recently discovered that the infamous North Korean hacking collective Lazarus has leveraged a previously undisclosed zero-day vulnerability in the Windows AFD.sys driver to achieve kernel-level infiltration of targeted systems.
Designated CVE-2024-38193, this vulnerability was brought to Microsoft’s attention and was addressed in their June 2024 Patch Tuesday releases. The Lazarus Group, also referred to as APT38, a notorious North Korean-backed hacking unit, exploited this flaw to gain unauthorized access to sensitive system components. The release of a patch by Microsoft highlights the critical nature of this security issue.
The Lazarus Group, operational since at least 2009, has a history of conducting high-profile cyberattacks across various sectors, including finance, government, and private enterprises. Researchers Luigino Camastra and Milanek identified the flaw in early June and observed the Lazarus Group using it to compromise the AFD.sys driver, an essential Windows component for advanced file operations.
This vulnerability enabled attackers to bypass established security barriers, allowing them to access restricted system areas typically off-limits to users and administrators. To mask their activities, Lazarus deployed stealthy malware known as Fudmodule, which effectively evaded security software detection.
The exploitation of this zero-day flaw is particularly alarming given its potential impact on critical industries. Targets included professionals in the cryptocurrency and aerospace sectors, where the attackers sought to breach networks and pilfer cryptocurrencies to fund their operations.
The sophistication and high stakes of this attack underscore the growing ingenuity of cybercriminals targeting sensitive areas. In response, Microsoft has issued a crucial patch to address the vulnerability, facilitated by Gen Threat Labs, which provided Microsoft with comprehensive exploit details for a swift fix.
Microsoft stated, “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.”
This update is essential for safeguarding Windows users against potential breaches, and Microsoft strongly advises all users to apply the update promptly to maintain security.
As cyber threats continue to evolve, vigilance and proactive cybersecurity measures are crucial. Regular updates and awareness of potential vulnerabilities are vital for defending against advanced cyber threats like those posed by the Lazarus Group.



