
Lazarus Group Exploits Windows Zero-Day CVE-2026-68820 in Operation Dream Job Campaign
North Korean threat actor Lazarus is actively exploiting a Windows kernel-mode driver zero-day (CVE-2026-68820) to deploy the FudModule rootkit. The campaign targets defense and aerospace sectors globally.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-68820
- Source:
- Check Point
- Read Time:
- 4 min
Executive Summary
In the August 2026 Patch Tuesday cycle, Microsoft addressed a critical zero-day vulnerability, CVE-2026-68820, which has been actively exploited in the wild. The vulnerability, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys), allows attackers to escalate privileges to SYSTEM level. Intelligence indicates that the North Korean-linked threat actor, Lazarus Group, has been weaponizing this exploit since early July 2026 as part of their ongoing 'Operation Dream Job' campaign.
Threat Analysis
The Lazarus Group continues to demonstrate high technical sophistication by integrating kernel-level exploits into their infection chains. By targeting the AFD.sys driver, the attackers gain the ability to bypass standard security controls. This specific campaign focuses on high-value targets within the defense, aerospace, and aviation industries across Europe and India. The use of fraudulent recruitment lures remains a primary vector for initial access, followed by the deployment of the FudModule rootkit.
Technical Details
CVE-2026-68820 is a use-after-free vulnerability residing in the Windows kernel-mode driver afd.sys. Successful exploitation allows an unprivileged user to execute arbitrary code with SYSTEM privileges. Researchers at Check Point identified that the latest iteration of the FudModule rootkit, deployed via this exploit, is specifically tailored to support Windows 11 builds 26100 and 26200. The rootkit is designed to disable EDR telemetry, interfere with security product monitoring, and tamper with Windows Smart App Control, effectively blinding host-based defenses.
Attribution Assessment
Attribution is assigned to the Lazarus Group with high confidence based on the TTPs (Tactics, Techniques, and Procedures) observed, including the specific use of the FudModule rootkit and the thematic alignment with the long-standing 'Operation Dream Job' campaign. The infrastructure and targeting patterns are consistent with previous North Korean state-sponsored cyber espionage operations.
Implications
The exploitation of a kernel-mode driver zero-day poses a severe risk to enterprise environments. Because the exploit grants SYSTEM-level access, it effectively renders traditional user-mode security software ineffective. Organizations in the defense and critical infrastructure sectors are at the highest risk of data exfiltration and persistent surveillance.
Recommendations
- Immediate Patching: Organizations must prioritize the deployment of the August 2026 security updates, specifically targeting CVE-2026-68820.
- Endpoint Monitoring: Enhance monitoring for anomalous kernel-mode activity and unauthorized modifications to EDR configurations.
- User Awareness: Conduct targeted training for employees in sensitive sectors regarding sophisticated recruitment-based phishing lures.
- Threat Hunting: Review logs for indicators of compromise related to the FudModule rootkit and unusual AFD.sys driver interactions.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Cisco AsyncOS Zero-Day Under Active Exploitation: Immediate Patching Required

Arista Networks Issues Urgent Warning Over Actively Exploited VeloCloud Zero-Day Vulnerability

