Lazarus Exploits Windows AFD.sys Zero-Day To Hit Defense Firms
Security researchers have uncovered a fresh wave of attacks in which the North Korean state-sponsored hacking group Lazarus exploited a previously unknown Windows vulnerability to break into defense, aerospace, and aviation organizations across Europe, India, and South America.
The group weaponized the flaw, now tracked as CVE-2026-68820, as part of an updated version of its long-running Operation Dream Job campaign, which lures employees at target companies with fake job offers before delivering malware.

Check Point Research first documented the intrusions and traced Lazarus's use of the zero-day back to early July 2026, weeks before Microsoft shipped a fix. Microsoft addressed the bug on August 11 as part of its August 2026 Patch Tuesday release, which resolved roughly 400 vulnerabilities in total, including three zero-days.
CVE-2026-68820 was the only one of the three confirmed to have been exploited in the wild before a patch became available; the other two, CVE-2026-62832 and CVE-2026-72971, were publicly disclosed but not observed in active attacks.
CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, commonly known as AFD.sys. This driver ships by default on every modern Windows installation and serves as the kernel-level entry point for the Winsock networking protocol, making it an attractive target for attackers seeking to escalate privileges without relying on third-party or easily blocked drivers.
According to Microsoft's advisory, a locally authenticated attacker can run a specially crafted application to trigger a race condition in the driver, ultimately gaining SYSTEM-level privileges without any further user interaction.
Microsoft credited Check Point researchers Moshe Marelus and David Driker with reporting the flaw, and the company has not disclosed further technical details on the exploitation chain. The vulnerability affects Windows 11 builds 26100 and 26200, according to Check Point's analysis of the exploit code recovered from compromised systems.
This is not the first time Lazarus has weaponized a zero-day in AFD.sys. In 2024, the group exploited a separate use-after-free flaw in the same driver, tracked as CVE-2024-38193, to install its signature FudModule rootkit. That earlier campaign was linked to attacks on cryptocurrency professionals in Brazil and was discovered by researchers at Gen Digital. The group's return to the same driver two years later underscores how central AFD.sys has become to its kernel-level toolkit.
Check Point's report, titled "Shattering the Dream: When a Job Offer Becomes a Zero-Day Attack," found that Lazarus built its exploit for CVE-2026-68820 directly into an updated version of the FudModule kernel-mode rootkit. FudModule has been a hallmark of Lazarus operations for several years and is designed to disable the security telemetry that endpoint detection and response tools rely on to spot malicious activity.
The newest version retains previously documented capabilities, such as blinding EDR sensors and tampering with security products, and adds the ability to interfere with Smart App Control, a Windows feature meant to block untrusted applications from running. Researchers say this evolution reflects Lazarus's continued investment in stealth, allowing the rootkit to operate on fully updated Windows 11 systems while evading the very defenses designed to catch it.
Alongside the updated rootkit, Check Point identified a new backdoor called Troy, deployed on compromised machines to provide attackers with hands-on keyboard control. The malware supports 17 distinct commands, including capabilities such as:
- System and process reconnaissance
- File upload, download, deletion, and archive-based exfiltration
- Hidden, in-memory command execution and DLL injection
- Remote process termination and beacon configuration changes
Fake Job Offers And A Compromised Webmail Server
The latest Operation Dream Job wave followed Lazarus's well-established playbook of posing as recruiters to approach employees at targeted organizations, particularly those working on sensitive military technologies.
Check Point said the campaign concentrated heavily on the defense sector, with a specific focus on companies involved in surveillance sensors, drones, and robotics. Confirmed targeting extended into Western Europe, including France and Germany, as well as Brazil, giving the operation a genuinely global footprint.
In one notable case, Lazarus compromised an organization in France and repurposed its infrastructure to launch spear-phishing attacks against additional targets, a tactic that lets the group's messages appear to originate from a trusted, already-known source rather than an unfamiliar external sender.
Check Point also observed the group scanning for vulnerable installations of Roundcube, an open-source webmail platform, and compromising them using a newly identified PHP web shell called RelayShell. The attackers appear to have obtained leaked credentials to authenticate with Roundcube first, then exploited CVE-2025-49113, an older authenticated PHP object-deserialization vulnerability, to achieve remote code execution on the mail server.
Based on the number of unique identifiers recovered from the malware, researchers identified at least 17 servers infected with RelayShell. Check Point noted that abusing legitimate, already-compromised web infrastructure to relay malicious communications lets Lazarus's traffic blend in with normal webmail activity, making detection considerably harder for defenders monitoring network traffic for obviously suspicious connections.
The disclosure landed alongside Microsoft's August 2026 Patch Tuesday, one of the year's largest update cycles. Beyond the three zero-days, Microsoft resolved 42 vulnerabilities rated "Critical," the majority of which were remote code execution flaws, along with 176 elevation-of-privilege bugs and 110 additional remote code execution issues spread across products including Exchange Server, SharePoint, Office, and multiple Windows kernel and driver components.
Microsoft has said it expects the volume of monthly security updates to continue climbing as it increasingly relies on an AI-assisted vulnerability-discovery system to comb through its codebase. Lazarus is widely attributed to North Korea and has been active for well over a decade, historically splitting its operations between financially motivated cryptocurrency theft, used to fund the regime's weapons programs, and espionage campaigns against defense, aerospace, and technology organizations.
The group has been linked to the 2014 Sony Pictures hack, the 2017 WannaCry ransomware outbreak, and the 2022 theft of more than 617 million USD in cryptocurrency from the Ronin Bridge. The U.S. government currently offers a reward of up to 5 million USD for information on the group's activities.
Organizations, particularly those in the defense, aerospace, and aviation sectors, should treat this campaign as a reminder that both endpoint software and internet-facing web applications need continuous attention. Recommended steps include:
- Apply the August 2026 Windows security updates immediately to close CVE-2026-68820 and the two accompanying publicly disclosed zero-days
- Patch or take offline any outdated Roundcube installations vulnerable to CVE-2025-49113, and rotate credentials that may have been exposed in prior breaches
- Train staff to treat unsolicited recruitment messages and unfamiliar job-related file attachments with suspicion, especially those requesting a coding test or a downloaded project
- Deploy endpoint monitoring capable of detecting kernel-level tampering and rootkit behavior, since tools like FudModule are specifically designed to blind conventional EDR telemetry.
Check Point published a set of indicators of compromise, along with a YARA rule, to help security teams detect RelayShell infections on their own Roundcube deployments. Given Lazarus's demonstrated pattern of reusing AFD.sys as an escalation vector, defenders are also advised to monitor for anomalous driver-level activity even after this specific vulnerability has been patched, since the group has shown a willingness to return to the same subsystem with new exploits over time.
Share:
Karolis Liucveikis
Experienced software engineer, passionate about behavioral analysis of malicious apps
Author and general operator of PCrisk's News and Removal Guides section. Co-researcher working alongside Tomas to discover the latest threats and global trends in the cyber security world. Karolis has experience of over 8 years working in this branch. He attended Kaunas University of Technology and graduated with a degree in Software Development in 2017. Extremely passionate about technical aspects and behavior of various malicious applications.
PCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
DonatePCrisk security portal is brought by a company RCS LT.
Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.
Our malware removal guides are free. However, if you want to support us you can send us a donation.
Donate
▼ Show Discussion