Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Check Point Research has attributed exploitation of CVE-2026-68820 โ the afd.sys WinSock driver use-after-free patched in Microsoft's August 2026 Patch Tuesday release โ to the Lazarus Group's Operation Dream Job campaign. The North Korean state-sponsored group used the privilege-escalation flaw to gain SYSTEM access and deliver a never-before-seen backdoor against defence and aerospace companies in France, Germany, Brazil and India.
Key Facts
| Attribute | Detail |
|---|---|
| Actor | Lazarus Group (DPRK), Operation Dream Job |
| Vulnerability | CVE-2026-68820 (afd.sys), CVSS 7.0 โ see Cve 2026 68820 Afd Sys Winsock Uaf |
| Targets | Defence and aerospace companies in FR, DE, BR, IN |
| TTPs | Fake job offers on LinkedIn; malware delivery; local escalation to SYSTEM |
| Other attribution | Same flaw added to CISA KEV on 2026-08-11 (BOD 26-04) |
| CISA directive | Federal civilian agencies given two weeks to remediate |
Context
Operation Dream Job is Lazarus's long-running espionage and social-engineering campaign using fake-but-compelling job offers to target professionals, blending credential theft with backdoor deployment. The afd.sys exploitation means the August Patch Tuesday release should be treated as urgent across AU/NZ Windows estates (Essential Eight, NZISM patching expectations), and CISA's two-week federal remediation deadline is a reasonable benchmark for agencies.
Related Pages
- Cve 2026 68820 Afd Sys Winsock Uaf โ the afd.sys zero-day
- First Near Autonomous Ai Attack Documented On Taiwanese Government Target โ same-week state-actor AI offensive capability
Sources: raw/digests/Cyber-Digest-2026-08-13