
Lazarus Group Exploits Windows Zero-Day CVE-2026-68820 in Global Defense Sector Attacks
North Korean threat actors are leveraging a Windows kernel-mode driver zero-day to deploy the FudModule rootkit. The campaign, dubbed Operation Dream Job, targets defense firms across Europe and South America.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-68820
- Source:
- Microsoft MSTIC
- Read Time:
- 4 min
Executive Summary
In August 2026, security researchers identified that the North Korean-linked Lazarus Group has been actively exploiting a zero-day vulnerability, tracked as CVE-2026-68820, to compromise high-value targets in the global defense sector. The vulnerability, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys), allows attackers to escalate privileges to SYSTEM level. Microsoft addressed this flaw in the August 2026 Patch Tuesday updates, but evidence suggests the group had been weaponizing the exploit since early July 2026.
Threat Analysis
The Lazarus Group continues to evolve its 'Operation Dream Job' campaign, which utilizes sophisticated social engineering to gain initial access to defense organizations. Once a foothold is established, the attackers deploy a new iteration of the FudModule kernel-mode rootkit. This latest version is specifically designed to bypass modern security controls, including EDR telemetry and Smart App Control, allowing the threat actors to maintain persistence and exfiltrate sensitive data related to military technologies such as drones, robotics, and surveillance sensors.
Technical Details
CVE-2026-68820 resides in the afd.sys driver, a core component of the Windows networking stack. By triggering the use-after-free condition, the exploit grants the attacker arbitrary code execution within the kernel context. The FudModule rootkit, which is then deployed, performs direct kernel object manipulation to hide malicious processes and disable security monitoring tools. Analysis of the rootkit samples indicates they were compiled as early as July 7, 2026, confirming a significant window of exploitation prior to the official patch release.
Attribution Assessment
Attribution to the Lazarus Group is based on the TTPs (Tactics, Techniques, and Procedures) observed, including the specific use of the FudModule rootkit and the targeting profile consistent with previous Operation Dream Job campaigns. The infrastructure used for command-and-control, including compromised Roundcube instances, aligns with historical Lazarus activity patterns.
Implications
The exploitation of kernel-level vulnerabilities by state-sponsored actors poses a severe risk to organizations in the defense and critical infrastructure sectors. The ability to disable EDR telemetry renders traditional endpoint protection ineffective, necessitating a defense-in-depth strategy that includes robust network monitoring and behavioral analysis.
Recommendations
- Immediate Patching: Ensure all Windows systems are updated to the latest security baseline provided in the August 2026 Patch Tuesday release.
- Threat Hunting: Scan for indicators of compromise (IOCs) related to FudModule, specifically looking for unauthorized kernel-mode drivers and anomalous network traffic patterns.
- EDR Hardening: Review EDR configurations to ensure that kernel-level monitoring is active and that alerts for suspicious driver loading are prioritized.
- User Awareness: Continue training employees on the risks of spear-phishing and social engineering, particularly those in sensitive roles within the defense industry.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Cisco AsyncOS Zero-Day Under Active Exploitation: Immediate Patching Required

Arista Networks Issues Urgent Warning Over Actively Exploited VeloCloud Zero-Day Vulnerability

