Lazarus exploits Windows zero-day in defence attacks
North Korea-linked hackers exploited a previously unknown Windows vulnerability to gain the highest level of system privileges while targeting defence, aerospace and aviation organisations across several countries. The flaw, tracked as CVE-2026-68820, affects the Windows Ancillary Function Driver for WinSock, known as AFD. sys. Microsoft patched the vulnerability on August 11 after it was found…
North Korean hackers exploited a newly discovered Windows vulnerability to gain complete control over high-level systems in defense, aerospace, and aviation organizations worldwide. The flaw, labeled CVE-2026-68820, targets the Windows Ancillary Function Driver for WinSock, AFD.sys. Microsoft released a patch on August 11, addressing the vulnerability discovered during Operation Dream Job, a cyber-espionage campaign linked to the Lazarus Group.
This campaign targeted France, Germany, Brazil, and India, focusing on companies related to military technology, aviation, surveillance systems, drones, and robotics. The vulnerability had been exploited since early July, not just two months, as initially reported. CVE-2026-68820 is a use-after-free vulnerability, caused by a race condition in AFD.sys, a kernel component managing Windows network sockets.
Once an attacker has code running on a compromised computer, they can exploit this weakness to elevate their privileges to SYSTEM, effectively controlling the machine. The vulnerability was deemed significant, with a CVSS severity score of 7.0, and was the only one confirmed as actively exploited during the August security release.
The Lazarus Group employed social engineering techniques, posing as recruiters with enticing job offers from prominent companies. Victims were directed to malicious files or software disguised as legitimate tools for viewing job-related PDF documents. One infection chain employed a digitally signed PDF viewer, malicious DLL, and encrypted payload through DLL sideloading.
Another chain used SecurityPDF, a modified application based on the legitimate open-source MuPDF framework. This trojanized viewer was distributed through at least three websites, gaining prominent search results. SecurityPDF was designed to recognize specially prepared files masquerading as ordinary PDFs. Upon opening, it extracted and launched an encrypted executable payload, loading a backdoor named Troy.
This 64-bit malware, supporting 17 commands, allows attackers extensive control of infected computers. The attackers also utilized MISTPEN as an in-memory downloader, enabling communications through Microsoft Graph and OneDrive to blend malicious activity with legitimate network traffic. The Lazarus Group integrated CVE-2026-68820 into an updated version of the FudModule kernel rootkit, allowing the rootkit to operate with SYSTEM privileges and interfere with security monitoring.
Targeting newer Windows builds, the rootkit aimed to tamper with Windows Smart App Control and suppress security products. To make command-and-control infrastructure harder to identify, the attackers exploited compromised Roundcube webmail systems, infecting them with a PHP web shell named RelayShell.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.