
Lazarus Group Exploits Windows AFD.sys Zero-Day (CVE-2026-68820) to Deploy Enhanced FudModule Rootkit
Lazarus APT is exploiting a Windows kernel zero-day (CVE-2026-68820) to deploy the FudModule rootkit, targeting defense and aerospace sectors in Europe and India with high precision.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Europe, India
- Confidence:
- High Confidence
- CVE:
- CVE-2026-68820
- Source:
- Check Point Research
- Read Time:
- 5 min
Executive Summary
On August 12, 2026, Microsoft released its monthly security update addressing over 400 vulnerabilities, including a critical zero-day tracked as CVE-2026-68820. This vulnerability, located in the Windows Ancillary Function Driver for WinSock (afd.sys), has been actively exploited in the wild by the North Korean state-sponsored group Lazarus. The exploitation is part of a sophisticated campaign targeting defense and aerospace sectors globally. Encrygma analysts have observed that this flaw allows for local privilege escalation, enabling attackers to gain SYSTEM-level access on compromised Windows 11 systems. The speed at which this vulnerability was weaponized highlights the persistent threat posed by advanced persistent threat (APT) actors against critical infrastructure and defense supply chains.
Threat Analysis
The exploitation of CVE-2026-68820 is linked to the long-running "Operation Dream Job" campaign. Lazarus actors utilize social engineering, often posing as recruiters on professional networking sites, to deliver malicious payloads to employees in high-value industries. Recent intelligence from Lazarus hackers exploited Windows zero-day to target defense firms indicates a shift in tactics, with the group now specifically targeting Windows 11 builds 26100 and 26200. This precision suggests a deep understanding of modern Windows kernel internals and a focus on bypassing the latest security mitigations. The campaign has primarily focused on entities in Europe and India, seeking to exfiltrate sensitive aerospace and defense data.
Technical Details
CVE-2026-68820 is a use-after-free vulnerability within the afd.sys kernel-mode driver. The driver serves as the backbone for the Windows Sockets API. By triggering a race condition through a specially crafted application, a locally authenticated attacker can manipulate memory to execute code with SYSTEM privileges. According to Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days, the exploit is used to deploy a new version of the FudModule rootkit. This updated rootkit features advanced capabilities, including the ability to disable Endpoint Detection and Response (EDR) telemetry and tamper with Windows Smart App Control, effectively blinding security operations centers (SOCs) to the attacker's presence.
Attribution Assessment
Attribution to the Lazarus Group (also known as Diamond Sleet or APT38) is made with high confidence. The techniques, tactics, and procedures (TTPs) align perfectly with previous Lazarus operations, specifically the use of the FudModule rootkit and the "Operation Dream Job" social engineering lures. The targeting of defense and aerospace entities in Europe and India further supports this assessment, as these sectors are primary intelligence requirements for the North Korean regime. The group's ability to discover and weaponize kernel-level zero-days underscores their status as one of the most capable state-sponsored threats currently active.
Implications
The successful exploitation of a kernel-level zero-day represents a significant escalation in threat actor capabilities. By gaining SYSTEM privileges and deploying a rootkit, Lazarus can maintain persistent, stealthy access to sensitive environments. The ability to neutralize EDR solutions means that traditional detection mechanisms may fail to alert on subsequent lateral movement or data exfiltration. This poses a severe risk to intellectual property and national security information within the targeted sectors. Furthermore, the public disclosure of the exploit code could lead to other threat actors, including ransomware groups, adopting similar techniques.
Recommendations
Encrygma strongly recommends that organizations prioritize the deployment of the August 2026 Microsoft Security Updates to all Windows systems, particularly those running Windows 11. Given the active exploitation of CVE-2026-68820, patching should be completed within a 24-hour window for critical assets. Additionally, security teams should hunt for indicators of the FudModule rootkit, such as unauthorized modifications to kernel drivers or unexpected disabling of security services. Implementing strict application control and monitoring for unusual social engineering attempts via professional platforms is also advised to mitigate the initial infection vector.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Zero-Day Exploitation Hits Citrix NetScaler ADC and Gateway Appliances Globally

Global Intelligence Alert: Escalating Nation-State Exploitation of Edge Infrastructure in Q3 2026

