News Room
16
Share
Lazarus Group Leverages Windows Zero-Day CVE-2026-68820 in Global Defense Sector Espionage Campaign
criticalZero-Day Exploits

Lazarus Group Leverages Windows Zero-Day CVE-2026-68820 in Global Defense Sector Espionage Campaign

Lazarus Group is actively exploiting CVE-2026-68820, a Windows kernel zero-day, to deploy FudModule rootkits against defense firms, coinciding with critical SAP Commerce Cloud RCE exploitation.

17 August 2026Last updated 18 August 20265 min readCheck Point Research
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-68820, CVE-2026-58231
Source:
Check Point Research
Read Time:
5 min

Executive Summary

Encrygma intelligence has tracked a significant escalation in Lazarus Group activity following the disclosure of CVE-2026-68820. This Windows Ancillary Function Driver (AFD.sys) zero-day was patched in the August 2026 cycle but remains a primary vector for kernel-mode persistence. Simultaneously, critical Remote Code Execution (RCE) attempts against SAP Commerce Cloud (CVE-2026-58231) have surged since August 15, 2026, indicating a high-tempo period for both state-sponsored and opportunistic cybercriminal actors. The convergence of these threats necessitates immediate patching and enhanced monitoring of kernel-level events.

Threat Analysis

The Lazarus Group, a North Korean state-sponsored entity, has integrated CVE-2026-68820 into its long-standing 'Operation Dream Job' campaign. This campaign primarily targets defense, aerospace, and aviation sectors in Europe and India. The group utilizes sophisticated social engineering—specifically fraudulent job offers delivered via professional networking platforms—to deliver initial payloads. Once a foothold is established, the zero-day exploit is deployed to bypass modern Windows security mitigations and achieve kernel-level execution, allowing the actor to operate with the highest possible privileges on the victim machine.

Technical Details

CVE-2026-68820 is a use-after-free vulnerability within the Windows Ancillary Function Driver for WinSock (afd.sys). By manipulating kernel memory objects, attackers can elevate privileges from a standard user to SYSTEM. In recent observations, Lazarus has utilized this exploit to deploy a refined version of the FudModule rootkit. This rootkit employs Direct Kernel Object Manipulation (DKOM) to disable security software, including EDR and antivirus agents, by tampering with kernel structures. The exploit specifically targets Windows 11 builds 26100 and 26200, demonstrating the actor's focus on the latest enterprise environments. Furthermore, the SAP Commerce Cloud vulnerability (CVE-2026-58231) is being exploited via unauthenticated RCE, with honeypots detecting active scanning and exploitation attempts within 72 hours of the patch release.

Attribution Assessment

With high confidence, we attribute the exploitation of CVE-2026-68820 to the Lazarus Group (APT38). The tactics, techniques, and procedures (TTPs) align with historical 'Operation Dream Job' activity, including the use of specific command-and-control (C2) infrastructure and the FudModule malware family. The targeting of defense contractors in specific geographic regions further supports this assessment, as it aligns with the strategic interests of the North Korean state.

Implications

The successful deployment of a kernel-mode rootkit via a zero-day represents a critical threat to organizational integrity. Once the FudModule rootkit is active, the actor gains near-total control over the host, making detection via standard user-mode tools nearly impossible. The speed at which other vulnerabilities, such as the SAP Commerce Cloud RCE, are being weaponized suggests that organizations have a shrinking window—often less than 48 to 72 hours—to apply critical patches before active exploitation begins. This 'patch gap' is being aggressively exploited by both APTs and ransomware affiliates.

Recommendations

Encrygma recommends immediate deployment of the Microsoft August 2026 security updates, prioritizing systems running Windows 11. Organizations should also apply the SAP Commerce Cloud patch for CVE-2026-58231 immediately. Security teams should monitor for unusual afd.sys activity and implement robust EDR policies that detect kernel-level tampering and DKOM techniques. Network segmentation of sensitive R&D environments is essential to mitigate the impact of a successful Lazarus intrusion. Finally, employee awareness training regarding 'Operation Dream Job' social engineering tactics should be refreshed for all high-value targets.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo