News Room
16
Share
Lazarus Group Exploits Windows Kernel Zero-Day CVE-2026-68820 to Deploy Advanced FudModule Rootkit
criticalZero-Day Exploits

Lazarus Group Exploits Windows Kernel Zero-Day CVE-2026-68820 to Deploy Advanced FudModule Rootkit

North Korean threat actors are actively exploiting a zero-day in the Windows AFD.sys driver to gain SYSTEM privileges. The campaign targets defense firms using a sophisticated kernel-mode rootkit to bypass EDR.

23 August 2026Last updated 23 August 20265 min readCheck Point Research
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
Nation-State
Geography:
Europe
Confidence:
High Confidence
CVE:
CVE-2026-68820
Source:
Check Point Research
Read Time:
5 min

Executive Summary

Recent intelligence from Check Point Research and Microsoft MSTIC has confirmed that the North Korean-linked Lazarus Group has been actively exploiting a zero-day vulnerability in the Windows Ancillary Function Driver (AFD.sys) for WinSock. The vulnerability, tracked as CVE-2026-68820, was addressed in the August 2026 Patch Tuesday cycle but was utilized in the wild for several weeks prior to disclosure. The primary objective of this campaign is the deployment of a new, highly sophisticated version of the FudModule kernel-mode rootkit, designed to disable security software and maintain persistent access within high-value targets in the defense and aerospace sectors.

Threat Analysis

The exploitation occurs as part of a long-running campaign known as 'Operation Dream Job.' In this iteration, threat actors approach targets via professional networking platforms with fraudulent job offers. Once the victim executes a malicious payload disguised as a job description or application, the infection chain initiates. The attackers utilize CVE-2026-68820 to escalate privileges from a standard user to SYSTEM level. This elevation is critical as it allows the threat actor to bypass modern Windows security features and install drivers with kernel-level permissions. According to BleepingComputer, the exploit specifically targets Windows 11 builds 26100 and 26200, indicating a high degree of technical tailoring.

Technical Details

CVE-2026-68820 is a use-after-free vulnerability within the afd.sys driver, which serves as the entry point for the Windows Sockets (WinSock) API. By manipulating the driver's memory management, attackers can execute arbitrary code in kernel mode. Once SYSTEM privileges are achieved, the Lazarus Group deploys the FudModule rootkit. This version of FudModule is particularly dangerous because it employs Direct Kernel Object Manipulation (DKOM) to tamper with internal kernel structures. Technical analysis reveals that the rootkit can disable Endpoint Detection and Response (EDR) telemetry by unhooking callbacks and interfering with the Microsoft Defender for Endpoint service. Furthermore, researchers noted new capabilities for tampering with Smart App Control, effectively blinding security teams to subsequent malicious activities.

Attribution Assessment

Security researchers at Check Point and Microsoft have attributed this activity to the Lazarus Group (also known as Diamond Sleet or APT38) with high confidence. The attribution is based on the use of the FudModule rootkit, which is a signature tool of the group, as well as the 'Operation Dream Job' infrastructure and tactics. The compilation timestamps on the FudModule samples—dating back to July 7, 2026—suggest the group had access to the zero-day for over a month before the August 11 patch release.

Implications

The successful exploitation of kernel-level vulnerabilities represents a significant escalation in threat actor capabilities. By operating within the kernel, Lazarus can effectively 'go under' most user-mode security products. The targeting of defense firms in Europe, specifically France and Germany, suggests a strategic focus on industrial espionage and the theft of sensitive military technology. Organizations that have not yet applied the August 2026 security updates are at critical risk of persistent compromise that may be invisible to standard monitoring tools.

Recommendations

Encrygma recommends the following immediate actions:

  1. Immediate Patching: Prioritize the deployment of Microsoft's August 2026 security updates, specifically addressing CVE-2026-68820.
  2. Kernel Monitoring: Implement advanced monitoring for unauthorized driver loading and DKOM-related anomalies.
  3. Threat Hunting: Scan for indicators of the FudModule rootkit, including unusual modifications to EDR service configurations and unexpected kernel-mode callbacks.
  4. User Awareness: Reinforce training regarding social engineering tactics on LinkedIn and other professional platforms, particularly concerning unsolicited job offers involving file downloads.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo