News Room
16
Share
Lazarus Group Exploits Windows Zero-Day CVE-2026-68820 in Global Defense Sector Attacks
criticalZero-Day Exploits

Lazarus Group Exploits Windows Zero-Day CVE-2026-68820 in Global Defense Sector Attacks

North Korean threat actors are leveraging a Windows kernel-mode driver zero-day to deploy the FudModule rootkit. The campaign, dubbed Operation Dream Job, targets defense firms across Europe and South America.

25 August 2026Last updated 25 August 20264 min readMicrosoft MSTIC
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-68820
Source:
Microsoft MSTIC
Read Time:
4 min

Executive Summary

In August 2026, security researchers identified that the North Korean-linked Lazarus Group has been actively exploiting a zero-day vulnerability, tracked as CVE-2026-68820, to compromise high-value targets in the global defense sector. The vulnerability, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys), allows attackers to escalate privileges to SYSTEM level. Microsoft addressed this flaw in the August 2026 Patch Tuesday updates, but evidence suggests the group had been weaponizing the exploit since early July 2026.

Threat Analysis

The Lazarus Group continues to evolve its 'Operation Dream Job' campaign, which utilizes sophisticated social engineering to gain initial access to defense organizations. Once a foothold is established, the attackers deploy a new iteration of the FudModule kernel-mode rootkit. This latest version is specifically designed to bypass modern security controls, including EDR telemetry and Smart App Control, allowing the threat actors to maintain persistence and exfiltrate sensitive data related to military technologies such as drones, robotics, and surveillance sensors.

Technical Details

CVE-2026-68820 resides in the afd.sys driver, a core component of the Windows networking stack. By triggering the use-after-free condition, the exploit grants the attacker arbitrary code execution within the kernel context. The FudModule rootkit, which is then deployed, performs direct kernel object manipulation to hide malicious processes and disable security monitoring tools. Analysis of the rootkit samples indicates they were compiled as early as July 7, 2026, confirming a significant window of exploitation prior to the official patch release.

Attribution Assessment

Attribution to the Lazarus Group is based on the TTPs (Tactics, Techniques, and Procedures) observed, including the specific use of the FudModule rootkit and the targeting profile consistent with previous Operation Dream Job campaigns. The infrastructure used for command-and-control, including compromised Roundcube instances, aligns with historical Lazarus activity patterns.

Implications

The exploitation of kernel-level vulnerabilities by state-sponsored actors poses a severe risk to organizations in the defense and critical infrastructure sectors. The ability to disable EDR telemetry renders traditional endpoint protection ineffective, necessitating a defense-in-depth strategy that includes robust network monitoring and behavioral analysis.

Recommendations

  1. Immediate Patching: Ensure all Windows systems are updated to the latest security baseline provided in the August 2026 Patch Tuesday release.
  2. Threat Hunting: Scan for indicators of compromise (IOCs) related to FudModule, specifically looking for unauthorized kernel-mode drivers and anomalous network traffic patterns.
  3. EDR Hardening: Review EDR configurations to ensure that kernel-level monitoring is active and that alerts for suspicious driver loading are prioritized.
  4. User Awareness: Continue training employees on the risks of spear-phishing and social engineering, particularly those in sensitive roles within the defense industry.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo