AIO APEX

Lazarus Group exploits Windows zero-day to hit defense firms across Europe and India

BleepingComputer
Share:
Lazarus Group exploits Windows zero-day to hit defense firms across Europe and India

North Korea’s Lazarus Group has been actively exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation companies across France, Germany, India, and Brazil, according to new research from Check Point published ahead of Microsoft’s August 2026 Patch Tuesday. Microsoft patched the flaw on August 12, 2026, flagging it as actively exploited in the wild. CISA has mandated that all US federal agencies apply the fix by August 25.

What the vulnerability does

CVE-2026-68820 is a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys), a kernel-mode component present on virtually all Windows 11 systems. Exploitation allows a locally authenticated user to trigger a race condition that elevates their privileges to SYSTEM level—without any interaction from the target. Microsoft’s August Patch Tuesday addressed 421 CVEs in total; this was the only one confirmed as actively exploited.

This is not Lazarus’s first AFD.sys zero-day. The group exploited a similar flaw in the same driver in 2024, which was also used to deploy FudModule. The repeat targeting of this driver suggests Lazarus has developed significant internal expertise in kernel-level Windows exploitation.

Operation Dream Job’s new toolkit

The attack is delivered through Operation Dream Job, Lazarus’s long-running social engineering campaign that uses fraudulent recruitment offers—posing as defense contractor job listings—to lure employees at target organizations. Once initial access is gained, the zero-day exploit elevates privileges and installs the latest version of the FudModule kernel-mode rootkit.

This new FudModule variant extends the group’s previous capabilities. Alongside its documented ability to disable EDR telemetry and interfere with security products, it now adds Smart App Control tampering—a technique that undermines one of Windows 11’s built-in defenses against unsigned applications.

Check Point also identified a previously undocumented backdoor called Troy, deployed alongside FudModule. Troy supports 17 commands including system and process reconnaissance, file upload and download, archive-based exfiltration, hidden command execution, remote process termination, in-memory DLL injection, and configuration updates for beacon timing. In at least one confirmed case, attackers compromised a French defense organization and used it as a staging post for spear-phishing additional targets.

What organizations should do

The August 2026 Patch Tuesday update patches CVE-2026-68820 and should be treated as urgent for any organization operating in the defense, aerospace, aviation, or government sectors. CISA’s August 25 deadline applies only to federal agencies, but the active exploitation timeline—Lazarus has been using the exploit since at least early July 2026—means the vulnerability was live in the wild for over a month before patching. Organizations that have not yet applied the update are running on borrowed time.

Check Point’s full technical analysis, including indicators of compromise for FudModule and the Troy backdoor, was published alongside the Patch Tuesday release, as first reported by BleepingComputer.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share:
Lazarus Group exploits Windows zero-day to hit defense firms across Europe and India | AIO APEX