← Back to Daily Briefing

The Lazarus Group exploited CVE-2026-68820, a critical zero-day vulnerability in the afd.sys (Ancillary Function Driver for Winsock) kernel driver of Microsoft Windows. The attack chain leverages social engineering via fraudulent job offers to establish initial user-level access, followed by a Local Privilege Escalation (LPE) exploit to achieve SYSTEM-level privileges. This elevation facilitates the deployment of the FudModule (v3) kernel-level rootkit for deep persistence and EDR evasion. Microsoft addressed the vulnerability in the August 2026 Patch Tuesday update.

  • Campaign Overview: Initial Access & Delivery

    • Deployment begins with highly targeted social engineering utilizing fake job offers.
    • Attackers trick victims into executing initial payloads to establish a low-privilege foothold.
    • Focuses on gaining a local presence before pivoting to kernel-mode exploitation.
  • Vulnerability Mechanics: CVE-2026-68820

    • Flaw located within afd.sys, the driver responsible for managing network socket operations.
    • Specifically exploited to achieve Local Privilege Escalation (LPE) from user-level to SYSTEM.
    • Allows the threat actor to bypass Windows security boundaries by manipulating kernel-mode socket handling.
  • Payload Analysis: FudModule Rootkit (v3)

    • Deployment occurs immediately following successful privilege escalation to SYSTEM.
    • Utilizes a sophisticated kernel-level rootkit designed for maximum stealth and persistence.
    • Engineered to evade standard security software and modern Endpoint Detection and Response (EDR) tools.
  • Impact & Remediation

    • Assigned a CVSS score of 7.0 (High) with confirmed active exploitation in the wild.
    • Potential impact includes full system compromise and unauthorized kernel-level access.
    • Remediation requires the immediate application of Microsoft's August 2026 security patches.

Related posts

  1. Cybersecurity News — Windows AFD.sys 0-Day Actively Exploited by Lazarus Hackers to Deploy FudModule Rootkit
  2. gbhackers.com — Windows AFD.sys Zero-Day Exploited by Lazarus Hackers to Gain SYSTEM Access
  3. blackhatnews.tokyo
  4. bleepingcomputer.com — Lazarus hackers exploited Windows zero-day to target defense firms
  5. simplysecuregroup.com — Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
  6. cybersecurity.pk — Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
  7. Security Affairs — North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
  8. SC Media — DPRK’s Lazarus Group exploits Windows zero-day in backdoor campaign
  9. falconinternet.net — Lazarus Had Your Windows Kernel for 5 Weeks — Patch Tuesday Fixed It
  10. SecurityWeek — Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
  11. News4Hackers — North Korean Hackers Exploit Windows Zero-Day Vulnerability, Latest Cybersecurity Threat
  12. En
  13. feeds.feedburner.com — Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
  14. Blackswan-cybersecurity
  15. Rewterz
  16. Gendigital
  17. Petri
  18. Darkreading
  19. Asec
  20. Ibm
  21. Securityaffairs
  22. Medium
  23. Windows
  24. Helpnetsecurity
  25. Cyberinsider
  26. Cisa
  27. Therecord
  28. The Record by Recorded Future — CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
  29. Infosecurity-magazine
  30. Thehackernews
  31. Research
  32. Home
  33. Cfr
  34. Daily
  35. Byteiota
  36. Youtube
  37. Cypro
  38. Cloudlinktech
  39. Notebookcheck

LINK COPIED TO CLIPBOARD