News Room
16
Share
Lazarus Group Exploits Windows WinSock Zero-Day CVE-2026-68820 to Deploy Advanced FudModule Rootkit
criticalZero-Day Exploits

Lazarus Group Exploits Windows WinSock Zero-Day CVE-2026-68820 to Deploy Advanced FudModule Rootkit

North Korean Lazarus hackers are exploiting a critical Windows WinSock driver zero-day (CVE-2026-68820) to deploy the FudModule rootkit, bypassing EDR and targeting global defense entities.

23 August 2026Last updated 23 August 20265 min readCheck Point Research
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
Nation-State
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-68820
Source:
Check Point Research
Read Time:
5 min

Executive Summary

Encrygma Intelligence is tracking the continued and expanded exploitation of CVE-2026-68820, a critical zero-day vulnerability in the Windows Ancillary Function Driver (AFD.sys) for WinSock. As of August 23, 2026, new telemetry indicates that the Lazarus Group has broadened its targeting beyond initial defense contractors to include aerospace research facilities in the Asia-Pacific region. This vulnerability, which allows for kernel-level privilege escalation, is being used to deploy the latest variant of the FudModule rootkit, enabling attackers to achieve total system compromise and EDR neutralization.

Threat Analysis

The Lazarus Group, a North Korean state-sponsored entity, is currently utilizing CVE-2026-68820 as part of its long-running "Operation Dream Job." The campaign leverages highly targeted spear-phishing via professional networking sites, where attackers pose as recruiters for major defense firms. The primary objective is the theft of sensitive intellectual property and military secrets. The integration of a zero-day exploit into this campaign marks a significant escalation in the group's capabilities, moving away from reliance on user-mode malware to more resilient kernel-mode persistence mechanisms.

Technical Details

CVE-2026-68820 is a use-after-free (UAF) vulnerability within the afd.sys driver, the kernel-mode component of the Windows Sockets (WinSock) ecosystem. The flaw occurs during the handling of specific socket IOCTLs, where a race condition allows an attacker to free a socket object and subsequently reuse the memory address. By carefully grooming the kernel pool, the Lazarus Group's exploit achieves a write-what-where primitive. This is then used to overwrite the PreviousMode field in the current thread's KTHREAD structure, granting the process the ability to read and write kernel memory from user space. The subsequent deployment of the FudModule rootkit utilizes Direct Kernel Object Manipulation (DKOM) to hide processes, files, and network connections, while also disabling the callback routines used by EDR agents to monitor system activity.

Attribution Assessment

Encrygma attributes this activity to the Lazarus Group (also known as Labyrinth Chollima or APT38) with high confidence. This attribution is based on the unique code signatures of the FudModule rootkit, the specific command-and-control infrastructure which overlaps with previous North Korean operations, and the distinct social engineering tactics characteristic of "Operation Dream Job." The group's focus on the defense and aerospace sectors aligns with the strategic intelligence requirements of the North Korean state.

Implications

The successful weaponization of CVE-2026-68820 highlights a critical gap in modern endpoint security. When an attacker gains kernel-level access, the integrity of the entire operating system is compromised, rendering user-mode security tools ineffective. This campaign demonstrates that sophisticated state-sponsored actors are increasingly targeting the underlying drivers of the Windows operating system to bypass advanced mitigations like Smart App Control and EDR. The long-term presence of a rootkit like FudModule allows for persistent, undetected data exfiltration and potential disruptive capabilities.

Recommendations

Organizations must prioritize the immediate installation of the August 2026 Microsoft security updates, which address CVE-2026-68820. Beyond patching, Encrygma recommends implementing strict application whitelisting and monitoring for unusual kernel-mode driver activity. Security teams should hunt for indicators of FudModule, such as the presence of unauthorized afd.sys interactions or the disabling of security-related system services. Furthermore, enhancing phishing defenses and implementing multi-factor authentication (MFA) for all external-facing services can help mitigate the initial access vectors used by the Lazarus Group.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo