Recent findings from Check Point Research reveal that the infamous North Korean hacking group, Lazarus, has been actively exploiting a critical Windows kernel vulnerability to deploy an enhanced version of its FudModule rootkit. This vulnerability, identified as CVE-2026-68820, resides within the AFD.sys file, responsible for managing network sockets in the Windows kernel. Microsoft addressed this flaw in their August Patch Tuesday update, following a prompt disclosure by Check Point.
Operation Dream Job Targeting Key Industries
The detection of this vulnerability forms part of a larger investigation into a resurgence of Operation Dream Job, a long-standing espionage campaign. This latest phase targets sectors such as defense, aerospace, and aviation, with activities confirmed in regions including Europe, India, and Brazil. The attackers employ social engineering techniques by posing as recruiters offering lucrative job opportunities, a tactic they have successfully utilized in the past to entice employees at high-value targets into opening malicious files.
Infection Chains and Techniques
Check Point identified two distinct infection chains used by the Lazarus group. The first chain involves DLL sideloading, where victims are tricked into downloading an encrypted ZIP archive containing a legitimate PDF viewer, a malicious DLL, and an encrypted payload disguised as a PDF. Once executed, the sideloaded DLL decrypts and launches the hidden payload in memory while displaying a decoy document to maintain the facade of legitimacy.
The second chain employs a trojanized PDF viewer named SecurityPDF, which is based on the open-source MuPDF framework. This modified viewer masquerades as a product from Enveil, a privacy technology company. The attackers have also created SEO-enhanced impersonation websites to rank highly in search results for terms like “Enveil SecurityPDF,” effectively separating the delivery of the malicious viewer from the booby-trapped PDF to evade detection.
Advanced Tactics and Recommendations
Both infection chains ultimately execute MISTPEN, an in-memory downloader that uses the Microsoft Graph API to retrieve additional modules from a OneDrive storage controlled by the attackers, encrypting traffic with AES. Following reconnaissance, a privilege-escalation module triggers the AFD.sys exploit, granting SYSTEM-level privileges to deploy the FudModule rootkit.
The latest variant of FudModule retains its core functionalities, including disabling security features and tampering with Smart App Control. Once privileges are elevated, the rootkit deploys a new MISTPEN instance to operate invisibly before introducing either the ForestTiger backdoor or the newly identified Troy implant, capable of executing commands and injecting DLLs in memory.
Lazarus routes its command-and-control traffic through compromised webmail and CMS sites, utilizing vulnerabilities like CVE-2025-49113. Organizations using Windows 11 are advised to apply the August patch to mitigate the CVE-2026-68820 exploit. Security teams, particularly in the defense sector, should monitor outgoing traffic for signs of compromised infrastructure used as covert relay points.
By leveraging advanced tactics and targeting critical industries, the Lazarus group continues to pose a significant threat to global cybersecurity. Vigilance and timely patching remain crucial in defending against such sophisticated attacks.
