Lazarus Group CVE-2026-68820: Windows Zero-Day Rootkit
2026-08-16 • Decryption Digest •
https://www.decryptiondigest.com/blog/lazarus-operation-dream-job-fudmodule-cve-2026-68820
Lazarus Group reportedly exploited the Windows `afd.sys` privilege-escalation flaw CVE-2026-68820 as a zero-day during an Operation Dream Job campaign targeting defense and aerospace organizations in four countries. Fake Enveil recruitment material delivered MISTPEN or Troy, after which the exploit elevated execution to SYSTEM and enabled installation of FudModule 3.1. The rootkit disabled Smart App Control and removed kernel callbacks used by EDR products, while ForestTiger provided persistent command access. Microsoft patched the flaw on August 11, 2026, and defenders were advised to block three campaign domains and hunt for abnormal DLL side-loading and Microsoft Graph API traffic.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | uxtramine.org | 2026-08-11 | 2026-08-16 |
| DOMAIN | enveil.online | 2026-08-11 | 2026-08-16 |
| DOMAIN | envell.xyz | 2026-08-11 | 2026-08-16 |