The North Korean state-sponsored group Lazarus Group has exploited a new Windows zero-day vulnerability to compromise organizations in the defense and aerospace sectors. The campaign, carried out in August 2026, targeted companies in France, Germany, Brazil, and India — further evidence of the growing threat posed by this highly capable nation-state actor.
CVE-2026-68820: A New Zero-Day in the AFD.sys Driver
How the Vulnerability Works
Tracked as CVE-2026-68820, the vulnerability resides in the Windows AFD.sys driver — the Ancillary Function Driver for WinSock. Attackers leveraged this flaw to escalate privileges to SYSTEM level on compromised machines.
Lazarus Group chained this exploit with well-known post-exploitation tools. Notably, the group deployed the FudModule rootkit to disable security solutions on infected hosts. Alongside it, a previously undocumented backdoor named Troy was distributed — marking its first observed appearance in the wild.
A Familiar Playbook
This is not the first time Lazarus has targeted AFD.sys. In February 2024, the group exploited CVE-2024-21338 in the AppLocker driver. In August 2024, they abused CVE-2024-38193, again in AFD.sys, pairing it with FudModule.
The pattern is consistent and deliberate. Lazarus identifies a trusted Windows driver, exploits it for privilege escalation, then deploys stealthy tooling to conceal its presence. The August 2026 attack follows exactly the same well-rehearsed sequence.
Operation Dream Job: The Campaign That Never Stops
Social Engineering as the Entry Point
The August 2026 intrusion is part of the long-running campaign known as Operation Dream Job. Lazarus initiates contact with targets through fake job offers, typically aimed at engineers, researchers, and defense industry professionals.
Attackers impersonate legitimate recruiters, sending documents, links, or invitations to online interviews. Once initial access is established, malware is deployed. This technique has previously proven effective against high-profile targets, including contractors linked to organizations like Lockheed Martin.
Why Defense and Aerospace Are in the Crosshairs
The choice of sectors is anything but coincidental. Targeted organizations work on drones, surveillance sensors, and advanced robotics — technologies with significant strategic and military value.
However, it is not only industry giants that face exposure. Lazarus systematically targets entire industrial ecosystems. Tier-2 suppliers and SMEs connected to the defense supply chain must also consider themselves at risk. The group actively seeks intelligence on dual-use technologies and sensitive procurement networks.
Operational Implications and Recommendations for CISOs
Patching and Attack Surface Reduction
The immediate priority for any organization is applying Microsoft’s latest patches. CVE-2026-68820 was addressed in the August 2026 Patch Tuesday update, with Microsoft flagging it as actively exploited in the wild.
Beyond rapid patching, organizations must work to limit local privilege escalation pathways. Lazarus consistently begins with low-privileged access before escalating to SYSTEM or kernel level. Reducing this attack surface is non-negotiable.
Defense in Depth: Concrete Steps to Take
Lazarus Group engineers its tools specifically to neutralize EDR solutions. For this reason, organizations must deploy security platforms with tamper protection and kernel-level visibility.
The following measures are strongly recommended:
- Vulnerable driver monitoring: block unauthorized drivers before they can be weaponized.
- Centralized logging: ensure full visibility across all system activity.
- Network segmentation: contain lateral movement in the event of a breach.
- Least privilege: enforce minimal permissions for every user and process.
- Awareness training for technical staff: educate employees on recognizing fake recruiting approaches.
In addition, organizations should establish clear verification procedures for unsolicited job offers. R&D professionals and engineers are the most frequently targeted individuals. A robust recruiter identity validation process can make a decisive difference.
Conclusion
Lazarus Group is not an opportunistic threat actor. It is a well-resourced, state-sponsored group operating with a long-term strategic agenda. The August 2026 attack once again demonstrates the group’s ability to combine zero-day exploits, advanced rootkits, and social engineering into a cohesive and devastating campaign.
For security leaders and CISOs, the message is unambiguous: reactive incident response is no longer enough. Organizations need a proactive, continuously updated, and resilient security posture. The threat is real, persistent, and evolving.
Sources:
- The Hacker News – Lazarus Exploits Windows Zero-Day
- BleepingComputer – Microsoft August 2026 Patch Tuesday
- The Register – 421 bugs in Microsoft’s Patch Tuesday release
Source: Original article
State-sponsored attacks like those carried out by Lazarus Group highlight the urgent need for rapid, secure threat intelligence sharing among organizations operating in the same sector. IsacChain enables the verified and secure exchange of indicators of compromise between ISACs and member companies, while also supporting automated and auditable NIS2 compliance. Every piece of shared intelligence is certified through blockchain verification, ensuring data integrity and non-repudiation. Discover how IsacChain can help your organization at www.isacchain.com