
Lazarus Group Exploits Windows WinSock Zero-Day CVE-2026-68820 to Deploy Advanced FudModule Rootkit
North Korean Lazarus hackers are exploiting a critical Windows WinSock driver zero-day (CVE-2026-68820) to deploy the FudModule rootkit, bypassing EDR and targeting global defense entities.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-68820
- Source:
- Check Point Research
- Read Time:
- 5 min
Executive Summary
Encrygma Intelligence is tracking the continued and expanded exploitation of CVE-2026-68820, a critical zero-day vulnerability in the Windows Ancillary Function Driver (AFD.sys) for WinSock. As of August 23, 2026, new telemetry indicates that the Lazarus Group has broadened its targeting beyond initial defense contractors to include aerospace research facilities in the Asia-Pacific region. This vulnerability, which allows for kernel-level privilege escalation, is being used to deploy the latest variant of the FudModule rootkit, enabling attackers to achieve total system compromise and EDR neutralization.
Threat Analysis
The Lazarus Group, a North Korean state-sponsored entity, is currently utilizing CVE-2026-68820 as part of its long-running "Operation Dream Job." The campaign leverages highly targeted spear-phishing via professional networking sites, where attackers pose as recruiters for major defense firms. The primary objective is the theft of sensitive intellectual property and military secrets. The integration of a zero-day exploit into this campaign marks a significant escalation in the group's capabilities, moving away from reliance on user-mode malware to more resilient kernel-mode persistence mechanisms.
Technical Details
CVE-2026-68820 is a use-after-free (UAF) vulnerability within the afd.sys driver, the kernel-mode component of the Windows Sockets (WinSock) ecosystem. The flaw occurs during the handling of specific socket IOCTLs, where a race condition allows an attacker to free a socket object and subsequently reuse the memory address. By carefully grooming the kernel pool, the Lazarus Group's exploit achieves a write-what-where primitive. This is then used to overwrite the PreviousMode field in the current thread's KTHREAD structure, granting the process the ability to read and write kernel memory from user space. The subsequent deployment of the FudModule rootkit utilizes Direct Kernel Object Manipulation (DKOM) to hide processes, files, and network connections, while also disabling the callback routines used by EDR agents to monitor system activity.
Attribution Assessment
Encrygma attributes this activity to the Lazarus Group (also known as Labyrinth Chollima or APT38) with high confidence. This attribution is based on the unique code signatures of the FudModule rootkit, the specific command-and-control infrastructure which overlaps with previous North Korean operations, and the distinct social engineering tactics characteristic of "Operation Dream Job." The group's focus on the defense and aerospace sectors aligns with the strategic intelligence requirements of the North Korean state.
Implications
The successful weaponization of CVE-2026-68820 highlights a critical gap in modern endpoint security. When an attacker gains kernel-level access, the integrity of the entire operating system is compromised, rendering user-mode security tools ineffective. This campaign demonstrates that sophisticated state-sponsored actors are increasingly targeting the underlying drivers of the Windows operating system to bypass advanced mitigations like Smart App Control and EDR. The long-term presence of a rootkit like FudModule allows for persistent, undetected data exfiltration and potential disruptive capabilities.
Recommendations
Organizations must prioritize the immediate installation of the August 2026 Microsoft security updates, which address CVE-2026-68820. Beyond patching, Encrygma recommends implementing strict application whitelisting and monitoring for unusual kernel-mode driver activity. Security teams should hunt for indicators of FudModule, such as the presence of unauthorized afd.sys interactions or the disabling of security-related system services. Furthermore, enhancing phishing defenses and implementing multi-factor authentication (MFA) for all external-facing services can help mitigate the initial access vectors used by the Lazarus Group.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Zero-Day Exploitation Surge: Citrix NetScaler and F5 BIG-IP Under Active Attack

Critical Zero-Day Exploitation Hits Citrix NetScaler ADC and Gateway Appliances Globally

