News Room
16
Share
Lazarus Group Exploits Windows Kernel Zero-Day in Targeted Defense Sector Attacks
criticalZero-Day Exploits

Lazarus Group Exploits Windows Kernel Zero-Day in Targeted Defense Sector Attacks

North Korean threat actors are leveraging a Windows AFD.sys zero-day (CVE-2026-68820) to deploy the FudModule rootkit against defense and aerospace firms in Europe and India.

21 August 2026Last updated 21 August 20264 min readMicrosoft MSTIC
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Europe and India
Confidence:
Confirmed
CVE:
CVE-2026-68820
Source:
Microsoft MSTIC
Read Time:
4 min

Executive Summary

In a sophisticated campaign identified as the latest iteration of 'Operation Dream Job,' the North Korean-linked Lazarus Group has been observed exploiting a critical zero-day vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys). The vulnerability, tracked as CVE-2026-68820, allows attackers to achieve privilege escalation to SYSTEM level. Microsoft addressed this flaw in the August 2026 Patch Tuesday updates, confirming its active exploitation in the wild since early July 2026.

Threat Analysis

The Lazarus Group continues to demonstrate high technical proficiency by integrating kernel-mode exploits into their established infection chains. By targeting employees in the defense, aerospace, and aviation sectors with fraudulent recruitment lures, the group gains initial access before deploying the FudModule rootkit. This rootkit is specifically designed to bypass modern security controls, including EDR telemetry and Smart App Control, allowing the attackers to maintain persistent, stealthy access to sensitive environments.

Technical Details

CVE-2026-68820 is a use-after-free vulnerability residing within the AFD.sys driver, a core component of the Windows networking stack. The exploit specifically targets Windows 11 builds 26100 and 26200. Upon successful exploitation, the attacker gains the ability to execute arbitrary code with kernel-level privileges. The latest version of the FudModule rootkit deployed via this exploit features advanced anti-forensic capabilities, including the ability to disable security product monitoring and manipulate system-level processes to evade detection by standard endpoint protection platforms.

Attribution Assessment

Based on the TTPs (Tactics, Techniques, and Procedures) observed—specifically the use of 'Operation Dream Job' lures and the deployment of the FudModule rootkit—the activity is attributed with high confidence to the Lazarus Group. This actor is known for its strategic focus on defense and financial intelligence gathering, often utilizing zero-day exploits to compromise high-value targets in the global defense industrial base.

Implications

The successful exploitation of a kernel-mode driver highlights the ongoing risk posed by sophisticated actors capable of developing or acquiring high-end exploits. Organizations in the defense and critical infrastructure sectors are at elevated risk, as the ability to bypass EDR telemetry renders traditional signature-based detection ineffective against this specific threat vector.

Recommendations

  1. Immediate Patching: Ensure all Windows systems are updated to the latest security baseline provided in the August 2026 Microsoft security updates to remediate CVE-2026-68820.
  2. Enhanced Monitoring: Implement behavioral analysis to detect anomalous kernel-mode activity and unauthorized modifications to EDR telemetry services.
  3. User Awareness: Conduct targeted security training for employees in sensitive roles regarding the risks of 'Operation Dream Job' style social engineering and recruitment-based phishing.
  4. Least Privilege: Enforce strict least-privilege access policies to limit the potential impact of successful privilege escalation attempts.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo