Lazarus Group CVE-2026-68820: Windows Zero-Day Rootkit

2026-08-16 Decryption Digest

https://www.decryptiondigest.com/blog/lazarus-operation-dream-job-fudmodule-cve-2026-68820

Thumbnail for Lazarus Group CVE-2026-68820: Windows Zero-Day Rootkit

Lazarus Group reportedly exploited the Windows `afd.sys` privilege-escalation flaw CVE-2026-68820 as a zero-day during an Operation Dream Job campaign targeting defense and aerospace organizations in four countries. Fake Enveil recruitment material delivered MISTPEN or Troy, after which the exploit elevated execution to SYSTEM and enabled installation of FudModule 3.1. The rootkit disabled Smart App Control and removed kernel callbacks used by EDR products, while ForestTiger provided persistent command access. Microsoft patched the flaw on August 11, 2026, and defenders were advised to block three campaign domains and hunt for abnormal DLL side-loading and Microsoft Graph API traffic.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN uxtramine.org 2026-08-11 2026-08-16
DOMAIN enveil.online 2026-08-11 2026-08-16
DOMAIN envell.xyz 2026-08-11 2026-08-16

Related Actors

Related Reports

« Back