Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Lazarus Group Exploits Windows Vulnerability for Rootkit Deployment

Lazarus Group Exploits Windows Vulnerability for Rootkit Deployment

Posted on August 12, 2026 By CWS

Recent findings from Check Point Research reveal that the infamous North Korean hacking group, Lazarus, has been actively exploiting a critical Windows kernel vulnerability to deploy an enhanced version of its FudModule rootkit. This vulnerability, identified as CVE-2026-68820, resides within the AFD.sys file, responsible for managing network sockets in the Windows kernel. Microsoft addressed this flaw in their August Patch Tuesday update, following a prompt disclosure by Check Point.

Operation Dream Job Targeting Key Industries

The detection of this vulnerability forms part of a larger investigation into a resurgence of Operation Dream Job, a long-standing espionage campaign. This latest phase targets sectors such as defense, aerospace, and aviation, with activities confirmed in regions including Europe, India, and Brazil. The attackers employ social engineering techniques by posing as recruiters offering lucrative job opportunities, a tactic they have successfully utilized in the past to entice employees at high-value targets into opening malicious files.

Infection Chains and Techniques

Check Point identified two distinct infection chains used by the Lazarus group. The first chain involves DLL sideloading, where victims are tricked into downloading an encrypted ZIP archive containing a legitimate PDF viewer, a malicious DLL, and an encrypted payload disguised as a PDF. Once executed, the sideloaded DLL decrypts and launches the hidden payload in memory while displaying a decoy document to maintain the facade of legitimacy.

The second chain employs a trojanized PDF viewer named SecurityPDF, which is based on the open-source MuPDF framework. This modified viewer masquerades as a product from Enveil, a privacy technology company. The attackers have also created SEO-enhanced impersonation websites to rank highly in search results for terms like “Enveil SecurityPDF,” effectively separating the delivery of the malicious viewer from the booby-trapped PDF to evade detection.

Advanced Tactics and Recommendations

Both infection chains ultimately execute MISTPEN, an in-memory downloader that uses the Microsoft Graph API to retrieve additional modules from a OneDrive storage controlled by the attackers, encrypting traffic with AES. Following reconnaissance, a privilege-escalation module triggers the AFD.sys exploit, granting SYSTEM-level privileges to deploy the FudModule rootkit.

The latest variant of FudModule retains its core functionalities, including disabling security features and tampering with Smart App Control. Once privileges are elevated, the rootkit deploys a new MISTPEN instance to operate invisibly before introducing either the ForestTiger backdoor or the newly identified Troy implant, capable of executing commands and injecting DLLs in memory.

Lazarus routes its command-and-control traffic through compromised webmail and CMS sites, utilizing vulnerabilities like CVE-2025-49113. Organizations using Windows 11 are advised to apply the August patch to mitigate the CVE-2026-68820 exploit. Security teams, particularly in the defense sector, should monitor outgoing traffic for signs of compromised infrastructure used as covert relay points.

By leveraging advanced tactics and targeting critical industries, the Lazarus group continues to pose a significant threat to global cybersecurity. Vigilance and timely patching remain crucial in defending against such sophisticated attacks.

Cyber Security News Tags:CVE-2026-68820, cyber espionage, Cybersecurity, defense sector, DLL Sideloading, FudModule, Lazarus Group, North Korea, Operation Dream Job, Rootkit, social engineering, Windows vulnerability

Post navigation

Previous Post: Critical SharePoint Flaw Allows Remote Code Execution
Next Post: Critical SAP Commerce Cloud Vulnerability Alert

Related Posts

Critical Vulnerability in SonicWall Appliances Exposes Networks Critical Vulnerability in SonicWall Appliances Exposes Networks Cyber Security News
Recurring Supply‑Chain Lapses Expose UEFI Firmware to Pre‑OS Threats Recurring Supply‑Chain Lapses Expose UEFI Firmware to Pre‑OS Threats Cyber Security News
Bloody Wolf Hackers Use NetSupport RAT in Targeted Attacks Bloody Wolf Hackers Use NetSupport RAT in Targeted Attacks Cyber Security News
Alice Blue Partners With AccuKnox For Regulatory Compliance Alice Blue Partners With AccuKnox For Regulatory Compliance Cyber Security News
Hackers Weaponizing Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability Hackers Weaponizing Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability Cyber Security News
Global Espionage Unveiled by Hackers’ Security Error Global Espionage Unveiled by Hackers’ Security Error Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • August 2026 ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact Updates
  • Critical SAP Commerce Cloud Vulnerability Alert
  • Lazarus Group Exploits Windows Vulnerability for Rootkit Deployment
  • Critical SharePoint Flaw Allows Remote Code Execution
  • Cisco Addresses Zero-Day Firewall Flaw Amid Active Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • August 2026 ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact Updates
  • Critical SAP Commerce Cloud Vulnerability Alert
  • Lazarus Group Exploits Windows Vulnerability for Rootkit Deployment
  • Critical SharePoint Flaw Allows Remote Code Execution
  • Cisco Addresses Zero-Day Firewall Flaw Amid Active Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark