ThreatCluster

Lazarus Group Exploits Windows AFD.sys Zero-Day Vulnerability

First seen 12 Aug 2026, 10:24 UTC CybersecuritynewsGbhackers 85% similarity 81

Article Content

Browse articles
ThreatCluster

The Lazarus group, linked to North Korea, is exploiting a newly discovered Windows zero-day vulnerability (CVE-2026-68820) in the AFD.sys driver, which provides SYSTEM-level access. This vulnerability is being leveraged in their Operation Dream Job campaign, targeting defense, aerospace, and aviation sectors globally, particularly in Europe and India. The flaw was identified by Check Point Research and was published on August 11, 2026. Microsoft has issued a patch for this vulnerability, but active exploitation is ongoing. The upgraded FudModule rootkit is being deployed as part of these attacks, indicating a sophisticated level of threat. Organizations in the affected sectors are urged to apply the patch immediately to mitigate risks.

Key Points: • Lazarus group exploits CVE-2026-68820 in AFD.sys for SYSTEM-level access. • Targeted sectors include defense, aerospace, and aviation in Europe and India. • Microsoft released a patch on August 11, 2026, but attacks are still active.

ThreatCluster AI How this analysis works

Timeline

2026-08-11
CVE-2026-68820 published
Check Point Research identified a zero-day vulnerability in AFD.sys, allowing SYSTEM-level access.
Gbhackers
2026-08-11
CISA adds CVE-2026-68820 to KEV list
CISA classified the vulnerability as actively exploited, prompting immediate attention from organizations.
Gbhackers
2026-08-12
Lazarus group exploits vulnerability
The North Korean Lazarus group is actively using the zero-day to deploy an upgraded FudModule rootkit.
Cybersecuritynews

Community

Browse all →