
Lazarus Group Leverages CVE-2026-68820 Zero-Day in Global Aerospace Espionage Campaign
Lazarus Group is actively exploiting a Windows kernel zero-day (CVE-2026-68820) in the AFD.sys driver to deploy the 'Troy' backdoor against defense targets in France, Germany, and India.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2026-68820, CVE-2026-50656
- Source:
- Check Point Research
- Read Time:
- 5 min
Executive Summary
Encrygma intelligence analysts have identified a coordinated surge in exploitation activities targeting Windows kernel vulnerabilities. Most notably, the North Korean state-sponsored actor Lazarus Group has weaponized CVE-2026-68820, a critical zero-day in the Windows Ancillary Function Driver (AFD.sys). This vulnerability is currently being utilized to facilitate the deployment of a sophisticated new backdoor, dubbed 'Troy,' against high-value targets in the aerospace and defense sectors across Europe and the Asia-Pacific region. Concurrently, a new exploit chain named 'ShieldBreak' has surfaced, bypassing recent patches for Microsoft Defender and exacerbating the risk to enterprise environments.
Threat Analysis
The Lazarus Group continues to refine its 'Operation Dream Job' methodology. The current campaign utilizes sophisticated social engineering on professional networking platforms, where attackers pose as recruiters for prominent defense contractors like Lockheed Martin and Enveil. Victims are enticed with lucrative job offers and pressured into downloading 'job description' packages that contain trojanized PDF viewers.
Once the malicious viewer is executed, the group leverages CVE-2026-68820 to achieve kernel-level privileges. This zero-day exploitation is indicative of the group's maturing capabilities in low-level system exploitation. The primary objective appears to be persistent espionage and the exfiltration of sensitive aeronautics blueprints and proprietary defense research from organizations in France, Germany, Brazil, and India.
Technical Details
CVE-2026-68820 (CVSS 7.8): This is a use-after-free (UAF) vulnerability residing in afd.sys, the kernel-mode driver responsible for the Windows Sockets API. The flaw is triggered via a race condition during socket handle closure. By carefully timing IOCTL requests, an attacker can manipulate the driver into accessing a freed memory object, leading to a controlled write-what-where primitive. Lazarus uses this to overwrite the current process token with the SYSTEM token, effectively bypassing all local security boundaries.
'Troy' Backdoor: The payload is a multi-stage Remote Access Trojan (RAT). It utilizes DLL side-loading via a legitimate executable included in the fake job package. The Troy backdoor features modular encryption for its C2 traffic (typically over HTTPS) and includes commands for file exfiltration, screen capturing, and the deployment of additional kernel-mode rootkits to hide its presence from EDR solutions.
'ShieldBreak' (CVE-2026-50656 Bypass): In a parallel development, the researcher known as 'Chaotic Eclipse' has released a bypass for the July 2026 patch of Microsoft Defender's Malware Protection Engine. The ShieldBreak chain uses a logic flaw in how mpengine.dll handles symbolic links during scheduled scans, allowing for arbitrary file deletion or modification as SYSTEM, even on fully patched systems.
Attribution Assessment
Encrygma attributes this activity to the Lazarus Group (associated with North Korea's RGB) with high confidence. This assessment is based on the reuse of the 'Operation Dream Job' infrastructure, specific code overlaps between the 'Troy' backdoor and previous North Korean malware variants, and the geographic focus on regions relevant to Pyongyang’s strategic interests.
Implications
The exploitation of CVE-2026-68820 represents a significant escalation in the threat landscape. The ability of Lazarus to deploy zero-days in kernel-mode drivers demonstrates a high level of investment in exploit development. Furthermore, the failure of initial patches for Microsoft Defender (ShieldBreak) suggests that standard endpoint protection may be insufficient against determined adversaries in the current 2026 threat environment.
Recommendations
- Immediate Patching: Apply the August 2026 cumulative updates from Microsoft immediately to remediate CVE-2026-68820.
- Restrict Kernel Drivers: Implement Windows Defender Application Control (WDAC) policies to block unauthorized or vulnerable drivers from loading.
- Advanced Lure Detection: Enhance email and web gateway filters to identify trojanized document viewers and recruitment-themed attachments.
- EDR Hardening: Given the ShieldBreak bypass, enable additional Tamper Protection features and monitor for unauthorized modifications to
mpengine.dlland related registry keys.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Cisco AsyncOS Zero-Day Under Active Exploitation: Immediate Patching Required

Arista Networks Issues Urgent Warning Over Actively Exploited VeloCloud Zero-Day Vulnerability

