Live Cybersecurity News Ticker | Codekeeper

North Korea's Lazarus Group Exploits Windows Kernel Zero-Day to Deploy Upgraded Rootkit

Written by Content Team | Aug 12, 2026, 12:30:07 PM

North Korea's Lazarus group has been actively exploiting a Windows kernel zero-day, CVE-2026-68820, buried inside AFD.sys — the driver managing network sockets — to deploy an upgraded FudModule rootkit. Microsoft patched the flaw on August 11 following responsible disclosure by Check Point Research. It's the group's second AFD.sys zero-day, after CVE-2024-38193.

The attacks are part of Operation Dream Job, targeting defense, aerospace and aviation sectors across Europe, India and Brazil. Lazarus posed as recruiters to trick employees into opening malicious files, and also seeded SEO-optimised phishing sites pushing a fake "SecurityPDF" app. The payload delivers SYSTEM-level access and FudModule v3.1, which blinds EDR tools and over 90 ETW providers.

Command and control runs through hijacked legitimate sites rather than dedicated servers — Roundcube webmail instances plus WordPress and PrestaShop sites running a web shell called RelayShell, across at least 17 relay nodes.

Windows 11 builds 26100 and 26200 are affected — apply August's Patch Tuesday update immediately, and check outbound traffic to Roundcube and CMS infrastructure.

Source: Cybersecurity News