
Lazarus Group Exploits Windows Zero-Day CVE-2026-68820 to Deploy FudModule Rootkit
Microsoft's August 2026 Patch Tuesday addresses 421 vulnerabilities, including an actively exploited zero-day in the Windows AFD.sys driver used by the Lazarus Group to install the FudModule rootkit.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-68820
- Source:
- Check Point
- Read Time:
- 4 min
Executive Summary
On August 11, 2026, Microsoft released its monthly security updates, addressing a staggering 421 vulnerabilities across its ecosystem. Among these, the most critical is CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys). This vulnerability has been confirmed as actively exploited in the wild by the North Korean-linked threat actor, Lazarus Group, to achieve kernel-level privilege escalation.
Threat Analysis
The Lazarus Group has once again demonstrated its sophisticated capabilities by weaponizing a zero-day vulnerability to facilitate its 'Operation Dream Job' campaign. By exploiting CVE-2026-68820, the attackers gain SYSTEM-level privileges on compromised Windows 11 systems. This access is a prerequisite for the deployment of their latest iteration of the FudModule kernel-mode rootkit, which is designed to bypass modern security controls.
Technical Details
CVE-2026-68820 is a use-after-free flaw residing in the afd.sys driver, a core component of the Windows networking stack. When successfully exploited, it allows an attacker to manipulate kernel memory, effectively bypassing User Account Control (UAC) and other integrity checks. The Lazarus Group utilizes this exploit to inject the FudModule rootkit, which features advanced capabilities such as disabling EDR telemetry, interfering with third-party security products, and tampering with Windows Smart App Control. The exploit has been observed targeting specific Windows 11 builds (26100 and 26200).
Attribution Assessment
Security researchers at Check Point have attributed the exploitation of CVE-2026-68820 to the Lazarus Group. This attribution is based on the specific TTPs (Tactics, Techniques, and Procedures) observed, including the deployment of the FudModule rootkit and the targeting of defense industry personnel, which aligns with the group's historical 'Operation Dream Job' activity. The precision of the exploit suggests a high level of investment in vulnerability research.
Implications
The exploitation of a kernel-mode driver vulnerability poses a severe risk to enterprise environments. Because the exploit grants SYSTEM privileges, it effectively renders standard user-mode security software blind to the attacker's subsequent actions. The sheer volume of patches released this month (421 CVEs) also creates a significant operational burden for IT teams, increasing the window of exposure for organizations that cannot immediately patch their infrastructure.
Recommendations
- Immediate Patching: Prioritize the deployment of the August 2026 security updates, specifically focusing on CVE-2026-68820, across all Windows endpoints.
- Endpoint Monitoring: Enhance EDR/XDR monitoring for suspicious kernel-mode activity and unauthorized driver loading, which are hallmarks of FudModule deployment.
- Vulnerability Management: Review and accelerate patch management workflows to handle the increased volume of monthly security disclosures.
- Threat Hunting: Conduct retrospective hunting for indicators of compromise (IOCs) related to the Lazarus Group's recent activity, particularly within defense and high-value target sectors.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Cisco AsyncOS Zero-Day Under Active Exploitation: Immediate Patching Required

Arista Networks Issues Urgent Warning Over Actively Exploited VeloCloud Zero-Day Vulnerability

