News Room
16
Share
Lazarus Group Exploits Windows Kernel Zero-Day CVE-2026-68820 in Global Defense Sector Campaign
criticalZero-Day Exploits

Lazarus Group Exploits Windows Kernel Zero-Day CVE-2026-68820 in Global Defense Sector Campaign

North Korean threat actor Lazarus is actively exploiting a zero-day in the Windows afd.sys driver to deploy the FudModule rootkit, targeting defense and aerospace entities worldwide.

19 August 2026Last updated 20 August 20264 min readCheck Point Research
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2026-68820
Source:
Check Point Research
Read Time:
4 min

Executive Summary

Encrygma intelligence has tracked the active exploitation of CVE-2026-68820, a critical zero-day vulnerability in the Windows Ancillary Function Driver (afd.sys). Recent telemetry and research from Check Point Research confirm that the North Korean-linked Lazarus Group has integrated this exploit into their long-standing "Operation Dream Job" campaign. The vulnerability allows for local privilege escalation to SYSTEM level, which the actors are leveraging to deploy an updated version of the FudModule rootkit. This campaign primarily targets defense, aerospace, and aviation organizations across Europe and India.

Threat Analysis

The Lazarus Group (also known as Diamond Sleet or Labyrinth Chollima) continues to demonstrate high technical proficiency by weaponizing zero-day vulnerabilities shortly after discovery—or in this case, prior to public patching. The current campaign utilizes fraudulent recruitment offers as an initial infection vector. Once a target is lured into executing a malicious payload, the CVE-2026-68820 exploit is triggered to bypass Windows security boundaries. This activity represents a significant escalation in Lazarus's capabilities, specifically targeting modern Windows 11 environments to maintain persistent access to high-value networks.

Technical Details

CVE-2026-68820 is a use-after-free vulnerability residing in the afd.sys kernel-mode driver, which serves as the entry point for the Windows Sockets (Winsock) API. The flaw is triggered via a race condition during the handling of socket objects. By carefully timing I/O requests, an attacker can manipulate memory to execute arbitrary code in kernel mode. Intelligence indicates the exploit specifically targets Windows 11 builds 26100 and 26200. Upon successful exploitation, the Lazarus Group deploys the FudModule rootkit. This latest iteration of FudModule includes advanced features to disable Endpoint Detection and Response (EDR) telemetry and tamper with Windows Smart App Control, effectively blinding security operations centers (SOCs) to the intrusion.

Attribution Assessment

Attribution to the Lazarus Group is made with high confidence. The tactics, techniques, and procedures (TTPs) align with historical "Operation Dream Job" activity, including the use of specific infrastructure and the FudModule rootkit, which is a signature tool of this actor. The targeting of defense and aerospace sectors for espionage purposes is consistent with North Korean strategic interests and previous campaigns documented by SecurityWeek.

Implications

The ability to gain SYSTEM-level privileges via a kernel driver zero-day poses a severe risk to enterprise environments. Because the exploit operates at the kernel level, traditional user-mode security tools may fail to detect the initial escalation. Furthermore, the integration of EDR-blinding capabilities within the FudModule rootkit suggests that compromised systems may remain undetected for extended periods, allowing for deep lateral movement and sensitive data exfiltration.

Recommendations

Encrygma recommends the following immediate actions: 1. Immediate Patching: Prioritize the deployment of the August 2026 Microsoft Security Updates, specifically addressing CVE-2026-68820. 2. Kernel Monitoring: Implement monitoring for unusual calls to afd.sys and track unauthorized modifications to kernel-mode drivers. 3. EDR Integrity: Utilize EDR solutions with built-in tamper protection and monitor for sudden gaps in telemetry from high-value assets. 4. Phishing Defense: Conduct targeted awareness training for employees in sensitive roles regarding fraudulent recruitment outreach on professional networking platforms.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo