Microsoft has patched CVE-2026-68820, a critical zero-day vulnerability in the Windows Ancillary Function Driver (afd.sys) that was actively exploited in the wild. The vulnerability, a use-after-free weakness, allows a local attacker to escalate privileges to SYSTEM. Security researchers at Check Point Research have attributed the attacks to the North Korean state-sponsored threat actor Lazarus Group, which leveraged the flaw as part of its ongoing "Operation Dream Job" espionage campaign. The attackers used the exploit to deploy the FudModule rootkit, disable endpoint security products, and maintain persistence on systems within the global defense, aerospace, and aviation sectors.
The attack targets employees in high-value industries with sophisticated social engineering, often involving fake job offers. In this campaign, the initial access vector was a malicious PDF viewer named "SecurityPDF," which contained a decoy document and a backdoor payload called "Troy." Once executed on a victim's machine, the malware exploited CVE-2026-68820 to gain the highest level of system privileges. This elevation is a critical step that allows the attackers to deploy their kernel-mode rootkit, FudModule. The rootkit is designed to operate with SYSTEM-level permissions, enabling it to tamper with or disable security software like Endpoint Detection and Response (EDR) solutions, effectively blinding defenders to subsequent malicious activity.
The vulnerability CVE-2026-68820 is a use-after-free condition within the Ancillary Function Driver for WinSock (afd.sys), a kernel-mode driver fundamental to Windows networking. An attacker who has already gained initial access as a low-privileged user can run a specially crafted application to trigger a race condition. This leads to the driver using a memory block after it has been freed, allowing the attacker to manipulate memory and execute arbitrary code with kernel-level privileges.
Lazarus Group's attack chain is as follows:
The afd.sys driver has historically been a target for advanced actors due to its core role in the operating system and the high-impact potential of its vulnerabilities.
The exploitation of CVE-2026-68820 represents a significant threat to organizations, particularly those in the defense, aerospace, and aviation industries targeted by the Lazarus Group. A successful exploit grants attackers complete control over a compromised system, allowing for unrestricted data exfiltration, deployment of further malware (like ransomware), and lateral movement across the network. The ability to disable EDR and other security solutions means that follow-on activities may go completely undetected, leading to a deep and persistent compromise. The business impact includes intellectual property theft, espionage, and potential sabotage of sensitive projects.
No specific file hashes, IP addresses, or domains were provided in the source articles.
The following patterns could indicate related activity:
SecurityPDF.exe%TEMP%\Troy.dllAcroRd32.exe spawning cmd.exe or powershell.exe).Security teams should prioritize the detection of activities related to this campaign.
afd.sys in the System log, which could indicate failed exploit attempts. Correlate these with process creation events (Event ID 4688) to identify the source application.Immediate patching is the most critical mitigation. However, a defense-in-depth strategy is essential.
Apply the security patch from Microsoft to fix CVE-2026-68820.
Mapped D3FEND Techniques:
Use application control to prevent the execution of unauthorized malicious applications like 'SecurityPDF.exe'.
Train users to recognize and report social engineering attempts like fake job offers.
Deploy and maintain EDR/AV solutions to detect and block known malware payloads like 'Troy'.
Mapped D3FEND Techniques:
Enforce the principle of least privilege to limit the capabilities of an initial compromise.
Mapped D3FEND Techniques:

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.