FudModule is a kernel-mode rootkit used by Lazarus Group since at least 2022. Version 3.1 adds the ability to disable Windows Smart App Control and uses post-quantum cryptography (ML-KEM) for key exchange, making it more stealthy and resilient.
FudModule is a kernel-mode rootkit used by Lazarus Group since at least 2022. Version 3.1 adds the ability to disable Windows Smart App Control and uses post-quantum cryptography (ML-KEM) for key exchange, making it more stealthy and resilient.