News Room
16
Share
Lazarus Group Weaponizes CVE-2026-68820: AFD.sys Zero-Day Targets Global Defense Sector
criticalZero-Day Exploits

Lazarus Group Weaponizes CVE-2026-68820: AFD.sys Zero-Day Targets Global Defense Sector

North Korean threat actor Lazarus is actively exploiting a use-after-free vulnerability in the Windows WinSock driver (CVE-2026-68820) to deploy the FudModule rootkit against aerospace and defense entities.

22 August 2026Last updated 22 August 20265 min readCheck Point Research
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
Nation-State
Geography:
Europe and India
Confidence:
High Confidence
CVE:
CVE-2026-68820
Source:
Check Point Research
Read Time:
5 min

Executive Summary

Following the massive August 2026 Patch Tuesday release, which addressed over 400 vulnerabilities, Encrygma intelligence has tracked a significant escalation in the exploitation of CVE-2026-68820. This zero-day vulnerability, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys), is being actively leveraged by the North Korean state-sponsored Lazarus Group. The campaign, identified as a new evolution of 'Operation Dream Job,' specifically targets defense, aerospace, and aviation organizations across Europe and India. The primary objective appears to be the deployment of a sophisticated kernel-mode rootkit to facilitate long-term espionage and data exfiltration.

Threat Analysis

The Lazarus Group has demonstrated a high degree of technical agility by incorporating CVE-2026-68820 into their existing infection chains within weeks of its discovery. The attack typically begins with highly targeted spear-phishing emails disguised as lucrative job opportunities from prominent defense contractors. Once a victim interacts with the malicious payload, the exploit triggers the AFD.sys vulnerability to bypass Windows security boundaries. Unlike previous iterations, this campaign shows a refined focus on Windows 11 builds 26100 and 26200, suggesting the actors are specifically targeting modern enterprise environments where traditional security controls are expected to be more robust.

Technical Details

CVE-2026-68820 is a critical elevation of privilege (EoP) vulnerability residing in the afd.sys driver, which serves as the entry point for the Windows Sockets (WinSock) API. The exploit utilizes a use-after-free condition to gain kernel-level execution privileges. Once administrative control is achieved, the attackers deploy the latest version of the 'FudModule' rootkit. This rootkit is particularly dangerous because it employs Direct Kernel Object Manipulation (DKOM) to blind Endpoint Detection and Response (EDR) tools. By tampering with kernel structures, FudModule can hide processes, files, and network connections, effectively rendering the infected system invisible to standard security monitoring solutions. Analysis indicates the rootkit now includes specific modules to disable telemetry for top-tier EDR vendors.

Attribution Assessment

Encrygma aligns with reports from Check Point Research and Microsoft MSTIC, attributing this activity to the Lazarus Group (also tracked as Diamond Sleet or APT38) with high confidence. The attribution is based on the reuse of the FudModule rootkit, the 'Operation Dream Job' social engineering tactics, and the specific targeting of defense-related intellectual property. The infrastructure used for command-and-control (C2) also overlaps with known North Korean state-sponsored clusters, further solidifying the link to Pyongyang's strategic intelligence requirements.

Implications

The exploitation of a kernel-level zero-day in a core Windows component like afd.sys represents a severe threat to the global defense supply chain. The ability of Lazarus to bypass modern Windows 11 protections and neutralize EDR solutions suggests that traditional perimeter and endpoint defenses are insufficient against this level of adversary. Organizations involved in military technology, surveillance, and robotics are at the highest risk of intellectual property theft, which could have long-term geopolitical consequences.

Recommendations

Encrygma strongly advises the following immediate actions:

  1. Immediate Patching: Prioritize the deployment of the August 2026 Microsoft security updates, specifically addressing CVE-2026-68820.
  2. Kernel Monitoring: Implement advanced monitoring for unauthorized modifications to kernel objects and unexpected behavior in the afd.sys driver.
  3. EDR Hardening: Enable tamper-protection features and utilize multi-layered detection strategies that do not rely solely on kernel-level telemetry.
  4. Threat Hunting: Conduct retrospective hunts for indicators of compromise (IoCs) related to the FudModule rootkit and Lazarus C2 infrastructure within defense-related networks.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo