News Room
16
Share
Lazarus Group Exploits Windows Zero-Day CVE-2026-68820 in Operation Dream Job Attacks
criticalZero-Day Exploits

Lazarus Group Exploits Windows Zero-Day CVE-2026-68820 in Operation Dream Job Attacks

The Lazarus APT group has been actively exploiting a Windows kernel-mode driver zero-day (CVE-2026-68820) to deploy the FudModule rootkit. Microsoft patched the flaw in the August 2026 Patch Tuesday update.

18 August 2026Last updated 20 August 20264 min readCheck Point
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Europe and India
Confidence:
Confirmed
CVE:
CVE-2026-68820
Source:
Check Point
Read Time:
4 min

Executive Summary

In the August 2026 Patch Tuesday cycle, Microsoft addressed a critical zero-day vulnerability, CVE-2026-68820, which has been actively exploited in the wild. Security researchers have attributed the exploitation to the North Korean-linked threat actor known as Lazarus Group. The vulnerability, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys), was leveraged to gain SYSTEM-level privileges on targeted systems, specifically within the defense, aerospace, and aviation sectors.

Threat Analysis

The Lazarus Group has integrated an exploit for CVE-2026-68820 into their ongoing 'Operation Dream Job' campaign. This campaign typically utilizes fraudulent recruitment lures to compromise employees at high-value organizations. By exploiting this kernel-mode vulnerability, the attackers successfully elevated their privileges, allowing them to bypass standard security controls and deploy a sophisticated, updated version of the FudModule rootkit.

Technical Details

CVE-2026-68820 is a use-after-free vulnerability residing in the afd.sys driver, which serves as the backbone for the Windows Sockets API. An attacker with local access can trigger a race condition by executing a specially crafted application, resulting in the escalation of privileges to SYSTEM. The latest iteration of the FudModule rootkit, deployed via this exploit, demonstrates advanced capabilities, including the ability to disable EDR telemetry, interfere with security products, and tamper with Windows Smart App Control. The exploit was specifically observed supporting Windows 11 builds 26100 and 26200.

Attribution Assessment

Attribution is assigned to the Lazarus Group based on the TTPs (Tactics, Techniques, and Procedures) observed, specifically the use of the FudModule rootkit and the targeting profile consistent with Operation Dream Job. The group has a documented history of exploiting AFD.sys vulnerabilities to maintain persistence and evade detection in sensitive environments.

Implications

The successful exploitation of this zero-day highlights the continued focus of state-sponsored actors on kernel-level vulnerabilities to achieve deep system persistence. Organizations in the defense and critical infrastructure sectors remain primary targets for such high-capability threat actors, necessitating robust endpoint monitoring and rapid patch deployment cycles.

Recommendations

  1. Immediate Patching: Organizations must prioritize the deployment of the August 2026 security updates to remediate CVE-2026-68820 across all Windows endpoints.
  2. Endpoint Monitoring: Enhance monitoring for suspicious activity related to the afd.sys driver and unusual kernel-mode operations.
  3. Security Awareness: Conduct targeted training for employees in high-risk sectors regarding recruitment-based social engineering lures.
  4. EDR Configuration: Ensure EDR solutions are configured to detect and block unauthorized attempts to tamper with security telemetry or kernel-mode drivers.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo