Lazarus Group Exploits Windows AFD.sys Zero-Day Vulnerability
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Lazarus group, linked to North Korea, is exploiting a newly discovered Windows zero-day vulnerability (CVE-2026-68820) in the AFD.sys driver, which provides SYSTEM-level access. This vulnerability is being leveraged in their Operation Dream Job campaign, targeting defense, aerospace, and aviation sectors globally, particularly in Europe and India. The flaw was identified by Check Point Research and was published on August 11, 2026. Microsoft has issued a patch for this vulnerability, but active exploitation is ongoing. The upgraded FudModule rootkit is being deployed as part of these attacks, indicating a sophisticated level of threat. Organizations in the affected sectors are urged to apply the patch immediately to mitigate risks.
Key Points: • Lazarus group exploits CVE-2026-68820 in AFD.sys for SYSTEM-level access. • Targeted sectors include defense, aerospace, and aviation in Europe and India. • Microsoft released a patch on August 11, 2026, but attacks are still active.