{
  "id": 696476,
  "title": "Lazarus exploits Windows zero-day in defence attacks",
  "url": "https://urgent.news/2026/08/12/lazarus-exploits-windows-zero-day-in-defence-attacks",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-12T20:29:22.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/lazarus-exploits-windows-zero-day-in-defence-attacks/"
  },
  "original_language": "en",
  "account": "North Korean hackers exploited a newly discovered Windows vulnerability to gain complete control over high-level systems in defense, aerospace, and aviation organizations worldwide. The flaw, labeled CVE-2026-68820, targets the Windows Ancillary Function Driver for WinSock, AFD.sys. Microsoft released a patch on August 11, addressing the vulnerability discovered during Operation Dream Job, a cyber-espionage campaign linked to the Lazarus Group. This campaign targeted France, Germany, Brazil, and India, focusing on companies related to military technology, aviation, surveillance systems, drones, and robotics. The vulnerability had been exploited since early July, not just two months, as initially reported. CVE-2026-68820 is a use-after-free vulnerability, caused by a race condition in AFD.sys, a kernel component managing Windows network sockets. Once an attacker has code running on a compromised computer, they can exploit this weakness to elevate their privileges to SYSTEM, effectively controlling the machine. The vulnerability was deemed significant, with a CVSS severity score of 7.0, and was the only one confirmed as actively exploited during the August security release. The Lazarus Group employed social engineering techniques, posing as recruiters with enticing job offers from prominent companies. Victims were directed to malicious files or software disguised as legitimate tools for viewing job-related PDF documents. One infection chain employed a digitally signed PDF viewer, malicious DLL, and encrypted payload through DLL sideloading. Another chain used SecurityPDF, a modified application based on the legitimate open-source MuPDF framework. This trojanized viewer was distributed through at least three websites, gaining prominent search results. SecurityPDF was designed to recognize specially prepared files masquerading as ordinary PDFs. Upon opening, it extracted and launched an encrypted executable payload, loading a backdoor named Troy. This 64-bit malware, supporting 17 commands, allows attackers extensive control of infected computers. The attackers also utilized MISTPEN as an in-memory downloader, enabling communications through Microsoft Graph and OneDrive to blend malicious activity with legitimate network traffic. The Lazarus Group integrated CVE-2026-68820 into an updated version of the FudModule kernel rootkit, allowing the rootkit to operate with SYSTEM privileges and interfere with security monitoring. Targeting newer Windows builds, the rootkit aimed to tamper with Windows Smart App Control and suppress security products. To make command-and-control infrastructure harder to identify, the attackers exploited compromised Roundcube webmail systems, infecting them with a PHP web shell named RelayShell.",
  "summary": "Arabian Post reports that North Korean hackers, associated with the Lazarus Group, have exploited a previously unknown Windows vulnerability to gain high-level system privileges in a targeted cyber attack. The flaw, identified as CVE-2026-68820, affects the Windows Ancillary Function Driver for WinSock, known as AFD.sys. Microsoft patched the vulnerability on August 11, after it was found to be actively exploited as part of Operation Dream Job, a long-running cyber-espionage campaign. The attackers primarily targeted organizations in France, Germany, Brazil, and India, focusing on companies involved in military technology, aviation, surveillance systems, drones, and robotics. The vulnerability, a use-after-free flaw caused by a race condition in AFD.sys, allows an attacker with existing code on a targeted computer to elevate privileges to SYSTEM, granting full control of the machine. Microsoft classified the flaw as important, assigning it a CVSS severity score of 7.0. The Lazarus Group's operation combined the privilege-escalation flaw with social engineering techniques, including posing as recruiters and distributing malicious files or software disguised as legitimate tools for viewing job-related PDF documents.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}