News Room
16
Share
Lazarus Group Exploits Windows AFD.sys Zero-Day (CVE-2026-68820) to Deploy Enhanced FudModule Rootkit
criticalZero-Day Exploits

Lazarus Group Exploits Windows AFD.sys Zero-Day (CVE-2026-68820) to Deploy Enhanced FudModule Rootkit

Lazarus APT is exploiting a Windows kernel zero-day (CVE-2026-68820) to deploy the FudModule rootkit, targeting defense and aerospace sectors in Europe and India with high precision.

17 August 2026Last updated 18 August 20265 min readCheck Point Research
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Europe, India
Confidence:
High Confidence
CVE:
CVE-2026-68820
Source:
Check Point Research
Read Time:
5 min

Executive Summary

On August 12, 2026, Microsoft released its monthly security update addressing over 400 vulnerabilities, including a critical zero-day tracked as CVE-2026-68820. This vulnerability, located in the Windows Ancillary Function Driver for WinSock (afd.sys), has been actively exploited in the wild by the North Korean state-sponsored group Lazarus. The exploitation is part of a sophisticated campaign targeting defense and aerospace sectors globally. Encrygma analysts have observed that this flaw allows for local privilege escalation, enabling attackers to gain SYSTEM-level access on compromised Windows 11 systems. The speed at which this vulnerability was weaponized highlights the persistent threat posed by advanced persistent threat (APT) actors against critical infrastructure and defense supply chains.

Threat Analysis

The exploitation of CVE-2026-68820 is linked to the long-running "Operation Dream Job" campaign. Lazarus actors utilize social engineering, often posing as recruiters on professional networking sites, to deliver malicious payloads to employees in high-value industries. Recent intelligence from Lazarus hackers exploited Windows zero-day to target defense firms indicates a shift in tactics, with the group now specifically targeting Windows 11 builds 26100 and 26200. This precision suggests a deep understanding of modern Windows kernel internals and a focus on bypassing the latest security mitigations. The campaign has primarily focused on entities in Europe and India, seeking to exfiltrate sensitive aerospace and defense data.

Technical Details

CVE-2026-68820 is a use-after-free vulnerability within the afd.sys kernel-mode driver. The driver serves as the backbone for the Windows Sockets API. By triggering a race condition through a specially crafted application, a locally authenticated attacker can manipulate memory to execute code with SYSTEM privileges. According to Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days, the exploit is used to deploy a new version of the FudModule rootkit. This updated rootkit features advanced capabilities, including the ability to disable Endpoint Detection and Response (EDR) telemetry and tamper with Windows Smart App Control, effectively blinding security operations centers (SOCs) to the attacker's presence.

Attribution Assessment

Attribution to the Lazarus Group (also known as Diamond Sleet or APT38) is made with high confidence. The techniques, tactics, and procedures (TTPs) align perfectly with previous Lazarus operations, specifically the use of the FudModule rootkit and the "Operation Dream Job" social engineering lures. The targeting of defense and aerospace entities in Europe and India further supports this assessment, as these sectors are primary intelligence requirements for the North Korean regime. The group's ability to discover and weaponize kernel-level zero-days underscores their status as one of the most capable state-sponsored threats currently active.

Implications

The successful exploitation of a kernel-level zero-day represents a significant escalation in threat actor capabilities. By gaining SYSTEM privileges and deploying a rootkit, Lazarus can maintain persistent, stealthy access to sensitive environments. The ability to neutralize EDR solutions means that traditional detection mechanisms may fail to alert on subsequent lateral movement or data exfiltration. This poses a severe risk to intellectual property and national security information within the targeted sectors. Furthermore, the public disclosure of the exploit code could lead to other threat actors, including ransomware groups, adopting similar techniques.

Recommendations

Encrygma strongly recommends that organizations prioritize the deployment of the August 2026 Microsoft Security Updates to all Windows systems, particularly those running Windows 11. Given the active exploitation of CVE-2026-68820, patching should be completed within a 24-hour window for critical assets. Additionally, security teams should hunt for indicators of the FudModule rootkit, such as unauthorized modifications to kernel drivers or unexpected disabling of security services. Implementing strict application control and monitoring for unusual social engineering attempts via professional platforms is also advised to mitigate the initial infection vector.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo