← Back to Daily Briefing

The Lazarus Group exploited CVE-2026-68820, a critical zero-day vulnerability in the afd.sys (Ancillary Function Driver for Winsock) kernel driver of Microsoft Windows. The attack chain leverages social engineering via fraudulent job offers to establish initial user-level access, followed by a Local Privilege Escalation (LPE) exploit to achieve SYSTEM-level privileges. This elevation facilitates the deployment of the FudModule (v3) kernel-level rootkit for deep persistence and EDR evasion. Microsoft addressed the vulnerability in the August 2026 Patch Tuesday update.

  • Campaign Overview: Initial Access & Delivery

    • Deployment begins with highly targeted social engineering utilizing fake job offers.
    • Attackers trick victims into executing initial payloads to establish a low-privilege foothold.
    • Focuses on gaining a local presence before pivoting to kernel-mode exploitation.
  • Vulnerability Mechanics: CVE-2026-68820

    • Flaw located within afd.sys, the driver responsible for managing network socket operations.
    • Specifically exploited to achieve Local Privilege Escalation (LPE) from user-level to SYSTEM.
    • Allows the threat actor to bypass Windows security boundaries by manipulating kernel-mode socket handling.
  • Payload Analysis: FudModule Rootkit (v3)

    • Deployment occurs immediately following successful privilege escalation to SYSTEM.
    • Utilizes a sophisticated kernel-level rootkit designed for maximum stealth and persistence.
    • Engineered to evade standard security software and modern Endpoint Detection and Response (EDR) tools.
  • Impact & Remediation

    • Assigned a CVSS score of 7.0 (High) with confirmed active exploitation in the wild.
    • Potential impact includes full system compromise and unauthorized kernel-level access.
    • Remediation requires the immediate application of Microsoft's August 2026 security patches.

Related posts

  1. Cybersecurity News — Windows AFD.sys 0-Day Actively Exploited by Lazarus Hackers to Deploy FudModule Rootkit
  2. gbhackers.com — Windows AFD.sys Zero-Day Exploited by Lazarus Hackers to Gain SYSTEM Access
  3. blackhatnews.tokyo
  4. bleepingcomputer.com — Lazarus hackers exploited Windows zero-day to target defense firms
  5. simplysecuregroup.com — Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
  6. cybersecurity.pk — Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
  7. Security Affairs — North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
  8. SC Media — DPRK’s Lazarus Group exploits Windows zero-day in backdoor campaign
  9. SecurityWeek — Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
  10. News4Hackers — North Korean Hackers Exploit Windows Zero-Day Vulnerability, Latest Cybersecurity Threat
  11. En
  12. feeds.feedburner.com — Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
  13. Blackswan-cybersecurity
  14. Rewterz
  15. Gendigital
  16. Petri
  17. Darkreading
  18. Asec
  19. Ibm
  20. Securityaffairs
  21. Medium
  22. Windows
  23. Helpnetsecurity
  24. Cyberinsider
  25. Cisa
  26. Therecord
  27. The Record by Recorded Future — CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
  28. Infosecurity-magazine
  29. Thehackernews
  30. Research
  31. Home
  32. Cfr
  33. Daily

LINK COPIED TO CLIPBOARD