
Lazarus Group Exploits Windows Zero-Day CVE-2026-68820 in Operation Dream Job Attacks
The Lazarus APT group has been actively exploiting a Windows kernel-mode driver zero-day (CVE-2026-68820) to deploy the FudModule rootkit. Microsoft patched the flaw in the August 2026 Patch Tuesday update.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Europe and India
- Confidence:
- Confirmed
- CVE:
- CVE-2026-68820
- Source:
- Check Point
- Read Time:
- 4 min
Executive Summary
In the August 2026 Patch Tuesday cycle, Microsoft addressed a critical zero-day vulnerability, CVE-2026-68820, which has been actively exploited in the wild. Security researchers have attributed the exploitation to the North Korean-linked threat actor known as Lazarus Group. The vulnerability, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys), was leveraged to gain SYSTEM-level privileges on targeted systems, specifically within the defense, aerospace, and aviation sectors.
Threat Analysis
The Lazarus Group has integrated an exploit for CVE-2026-68820 into their ongoing 'Operation Dream Job' campaign. This campaign typically utilizes fraudulent recruitment lures to compromise employees at high-value organizations. By exploiting this kernel-mode vulnerability, the attackers successfully elevated their privileges, allowing them to bypass standard security controls and deploy a sophisticated, updated version of the FudModule rootkit.
Technical Details
CVE-2026-68820 is a use-after-free vulnerability residing in the afd.sys driver, which serves as the backbone for the Windows Sockets API. An attacker with local access can trigger a race condition by executing a specially crafted application, resulting in the escalation of privileges to SYSTEM. The latest iteration of the FudModule rootkit, deployed via this exploit, demonstrates advanced capabilities, including the ability to disable EDR telemetry, interfere with security products, and tamper with Windows Smart App Control. The exploit was specifically observed supporting Windows 11 builds 26100 and 26200.
Attribution Assessment
Attribution is assigned to the Lazarus Group based on the TTPs (Tactics, Techniques, and Procedures) observed, specifically the use of the FudModule rootkit and the targeting profile consistent with Operation Dream Job. The group has a documented history of exploiting AFD.sys vulnerabilities to maintain persistence and evade detection in sensitive environments.
Implications
The successful exploitation of this zero-day highlights the continued focus of state-sponsored actors on kernel-level vulnerabilities to achieve deep system persistence. Organizations in the defense and critical infrastructure sectors remain primary targets for such high-capability threat actors, necessitating robust endpoint monitoring and rapid patch deployment cycles.
Recommendations
- Immediate Patching: Organizations must prioritize the deployment of the August 2026 security updates to remediate CVE-2026-68820 across all Windows endpoints.
- Endpoint Monitoring: Enhance monitoring for suspicious activity related to the afd.sys driver and unusual kernel-mode operations.
- Security Awareness: Conduct targeted training for employees in high-risk sectors regarding recruitment-based social engineering lures.
- EDR Configuration: Ensure EDR solutions are configured to detect and block unauthorized attempts to tamper with security telemetry or kernel-mode drivers.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Zero-Day Exploitation Hits Citrix NetScaler ADC and Gateway Appliances Globally

Critical Zero-Day Exploitation Confirmed in Citrix NetScaler ADC and Gateway Appliances

