Lazarus Windows Zero-Day: Operation Dream Job Returns
North Korea's Lazarus group exploited a Windows AFD.sys zero-day (CVE-2026-68820) for five weeks to breach defense firms and deploy the FudModule rootkit.
North Korea’s Lazarus Group ran a Windows kernel zero-day against defense contractors for at least five weeks before Microsoft could patch it, using fake job offers to lure engineers into an attack chain that ended with a stealthy rootkit installed deep inside the operating system. The vulnerability, now tracked as CVE-2026-68820, was disclosed alongside Microsoft’s August 2026 Patch Tuesday and detailed by Check Point Research, which tied the activity to a fresh wave of the long-running espionage campaign known as Operation Dream Job.
The story is not just another patched bug. It is a case study in how a state-backed group chains social engineering, a signed-software supply route, and a kernel-level exploit into a single quiet intrusion — and how long that machine can run before defenders even know the flaw exists.
The vulnerability: a WinSock kernel bug
CVE-2026-68820 lives in AFD.sys, the Ancillary Function Driver for WinSock — the kernel-mode driver that underpins the Windows Sockets API every networked application relies on. Because AFD.sys runs in the kernel and is reachable from ordinary user-mode code, it is a perennial target: a bug there offers a direct path from a normal process to full SYSTEM privileges.
The flaw is a use-after-free caused by improper synchronization when multiple threads manipulate socket-related state at the same time. Under a specific race condition, one code path frees a memory object while another continues to use it, producing memory corruption that a skilled attacker can shape into a privilege escalation. Microsoft rated the issue CVSS 7.0 — high rather than critical, because exploitation requires code already running on the machine — but that framing understates its role. In the Lazarus chain, the bug is the hinge that converts a foothold into total control. Our primer on zero-day vulnerabilities explains why a flaw under active exploitation before a fix exists is the most dangerous category defenders face.
The lure: fake jobs and a fake company
Operation Dream Job is a campaign Check Point and others have tracked for years, and its social-engineering playbook is consistent: pose as a recruiter, dangle a prestigious job at a well-known firm, and move the target off the corporate network onto attacker-controlled infrastructure. This latest wave refined the delivery into two parallel chains, both built around a PDF viewer — a file type defense and aerospace engineers open without a second thought.
In the first chain, the target receives a ZIP archive containing a legitimate PDF viewer and a malicious DLL. Opening the viewer triggers DLL side-loading: the trusted application silently loads the attacker’s library, which runs MISTPEN, an in-memory downloader. Notably, MISTPEN communicates through Microsoft OneDrive rather than a suspicious standalone server, blending its command-and-control traffic into normal cloud activity that most monitoring tools will not flag.
In the second chain, the target is steered to a search-engine-optimized website impersonating Enveil, a real privacy-technology company, to download SecurityPDF — a trojanized PDF viewer. When the victim opens a specially crafted document, the modified viewer executes hidden malware. Impersonating a genuine security vendor is a deliberate touch: it lends the download credibility with exactly the security-conscious audience Lazarus is targeting.
The payload: FudModule and a kernel foothold
Whichever route the victim takes, the chains converge. Each eventually loads an in-memory privilege-escalation module that fires the CVE-2026-68820 exploit, escalates to SYSTEM, and delivers FudModule — Lazarus’s kernel-mode rootkit — into the kernel. Running with kernel privileges, FudModule reportedly disabled or blinded 94 security-monitoring channels, systematically cutting the telemetry that endpoint-detection tools rely on to notice an intrusion. A rootkit operating at that level does not just hide files; it edits the operating system’s own view of what is happening, which is why kernel access is the prize attackers chase. For a sense of how a similar boundary-crossing works one layer up the stack, see our explainer on container escapes.
With monitoring neutralized, the operators installed ForestTiger, a persistent remote-access backdoor, giving them durable, low-visibility access to the compromised host. The end state is an espionage implant sitting on a defense engineer’s workstation, insulated from the security software meant to catch it.
The timeline: five weeks in the dark
The disclosure timeline is the part that should worry defenders most. Check Point Research reported the vulnerability to Microsoft on July 28, 2026. Microsoft confirmed it within days, formally assigned CVE-2026-68820 on August 5, and shipped the fix on August 11 as part of its August Patch Tuesday release — the same outsized rollup that addressed hundreds of other flaws.
But Lazarus was already inside. A compiled FudModule rootkit artifact recovered by researchers carries a build timestamp of July 7, 2026, meaning the group had a working exploit for the zero-day at least five weeks before a patch existed. For that entire window, fully updated Windows machines offered no defense against this specific privilege escalation. This is the recurring pattern behind Microsoft’s now-routine, ever-larger monthly releases — including its record July Patch Tuesday — where the raw CVE count matters far less than the handful of flaws attackers were already using.
Who was targeted
This wave zeroes in on the defense, aerospace, and aviation sectors, with confirmed activity spanning Europe, India, Brazil, and other regions. The victimology fits Lazarus’s mandate precisely: the group’s Operation Dream Job intrusions have long prioritized organizations with military, satellite, and advanced-manufacturing intellectual property, the kind of technical knowledge a sanctioned state cannot easily acquire through legitimate channels.
The choice of targets also explains the campaign’s care. Defense engineers are trained to be suspicious, so the operators invested in credibility — a real recruiter persona, a spoofed security vendor, a legitimately signed PDF application — to clear a higher-than-usual bar of skepticism. The sophistication is a function of the target set, not incidental polish.
The fix and what to do now
The remedy is unambiguous: apply Microsoft’s August 2026 security update, which patches CVE-2026-68820. Because the flaw requires local code execution to exploit, patching closes the escalation path even against a machine that has already been phished — but only if the earlier stages were not successful first. Defenders should therefore work both ends of the chain:
- Patch AFD.sys now. The August update is the definitive fix for the kernel bug; treat it as urgent given confirmed in-the-wild use by a capable actor.
- Hunt for the delivery stages. Look for suspicious DLL side-loading around PDF applications, unexpected child processes spawned by document viewers, and anomalous outbound traffic to OneDrive from workstations that have no business using it programmatically.
- Scrutinize software provenance. SecurityPDF impersonated a real vendor via SEO. Confirm that security and productivity tools are installed from verified, official sources rather than search-result downloads.
- Assume EDR can be blinded. FudModule’s ability to disable dozens of monitoring channels means endpoint telemetry alone is not a reliable tripwire. Network-level detection and kernel-integrity monitoring add coverage a compromised host cannot silence.
What it means
The Lazarus AFD.sys campaign is a compact demonstration of how modern state-sponsored intrusion actually works, and it carries three lessons beyond the immediate patch.
Social engineering is still the front door. For all the technical sophistication of a kernel zero-day and a rootkit that blinds 94 monitoring channels, the intrusion begins with a person opening a PDF they believe came from a recruiter. The most advanced exploit in the chain is worthless without that first human decision, which is why targeted defense organizations cannot treat awareness training and patching as separate programs. They are two halves of the same defense.
The patch gap is the real exposure. A five-week head start with a working exploit means that “fully patched” was not a meaningful state of protection for anyone in Lazarus’s crosshairs during July. Zero-days are, by definition, the window in which patching offers no help — a reminder that defense-in-depth, least privilege, and behavioral detection matter precisely because the patch is always late to the newest attack. The same compressed disclosure-to-exploitation dynamic played out in the recent GeoServer zero-day, where attackers moved within hours of public details.
What to watch next: whether CISA adds CVE-2026-68820 to its Known Exploited Vulnerabilities catalog, which would put a hard remediation deadline on U.S. federal operators; whether the same AFD.sys weakness or its neighbors surface in follow-on campaigns, given how reliably Lazarus reuses a proven privilege-escalation primitive; and whether other kernel drivers in the WinSock stack draw fresh scrutiny now that this one has paid off. For defense-sector defenders, the action item is not conditional: apply the August update, hunt the delivery chain, and assume the recruiter in your inbox may not be real.
Tagged
Keep reading
Chisato · · 5 min read PaperCut NG/MF Zero-Day: Patch All Versions Now
PaperCut is patching two zero-days in NG and MF — a pre-auth RCE and an access-control flaw — exploited in the wild. All versions affected. Apply Release 2.
Chisato · · 6 min read Chrome Zero-Day CVE-2026-85046: V8 Flaw Exploited
Google patched CVE-2026-85046, an actively exploited V8 type-confusion zero-day in Chrome and the sixth of 2026. Affected versions, the risk, and how to patch.
Chisato · · 5 min read Penetration Testing vs Vulnerability Scanning: What's the Difference
Vulnerability scanning automatically finds known weaknesses; penetration testing has a human actively try to exploit them. When to use each.