Cyber Security News

Windows AFD.sys 0-Day Actively Exploited by Lazarus Hackers to Deploy FudModule Rootkit

North Korea’s Lazarus group has been caught exploiting a Windows kernel 0-day vulnerability to deploy an upgraded version of its notorious FudModule rootkit, according to new research from Check Point Research.

The flaw, now tracked as CVE-2026-68820, lives inside AFD.sys, the Ancillary Function Driver that manages network sockets deep within the Windows kernel. Microsoft patched the bug on August 11 as part of its August Patch Tuesday release, just days after Check Point’s responsible disclosure.

The discovery is part of a broader investigation into a fresh wave of Operation Dream Job, a long-running espionage campaign Check Point has tracked since early 2026. This latest iteration zeroes in on the defense, aerospace, and aviation sectors, with confirmed activity across Europe, India, Brazil, and other regions.

The attackers pose as recruiters offering enticing job opportunities, a social engineering trick Lazarus has relied on for years to lure employees at high-value targets into opening malicious files.

Check Point identified two parallel infection chains. The first relies on DLL sideloading, where victims download an encrypted ZIP archive containing a legitimate signed PDF viewer, a malicious DLL named libmupdf.dll, and an encrypted payload disguised with a PDF extension.

Windows AFD.sys Zero-Day Attack Chain (Source : CheckPoint)

Once launched, the sideloaded DLL quietly extracts and decrypts a hidden payload in memory while showing the victim a decoy document, in one case a fake Lockheed Martin job description, to maintain the illusion of legitimacy.

The second chain uses a trojanized PDF viewer called SecurityPDF, built on the open-source MuPDF framework and modified to impersonate Enveil, a privacy technology firm.

The attackers even seeded SEO-optimized impersonation websites that rank highly in search results for terms like “Enveil SecurityPDF,” a tactic that lets them separate delivery of the malicious viewer from the delivery of the booby-trapped PDF and reduces the odds of detection.

Both chains ultimately execute MISTPEN, a lightweight in-memory downloader first documented by Mandiant in 2024. MISTPEN abuses the Microsoft Graph API to pull additional modules from attacker-controlled OneDrive storage, encrypting all traffic with AES.

It first deploys reconnaissance and screenshot modules to profile the victim machine, then, once the target is validated, delivers a privilege-escalation module that triggers the AFD.sys exploit.

Successful exploitation of CVE-2026-68820 hands the attackers SYSTEM-level privileges and launches FudModule, Lazarus’s signature kernel-mode rootkit first seen around 2021 and previously linked to a separate AFD.sys use-after-free bug, CVE-2024-38193.

The new variant, which Check Point labels FudModule v3.1, retains most of the rootkit’s core sabotage toolkit: it strips telemetry callbacks, disables minifilters, kills the NT Kernel Logger, and blinds over 90 ETW providers using a kill-list nearly identical to previous versions.

Notably, it drops the dedicated Microsoft Defender-disabling routine used in earlier releases and instead blinds security products through a generic suppression engine. It also adds a new capability to tamper with Smart App Control by resetting its verified-and-reputable policy state.

Once elevated, FudModule injects a fresh MISTPEN instance into a SYSTEM process, letting the attackers operate invisibly to most EDR tools before deploying ForestTiger, a long-documented Lazarus backdoor, or Troy, a newly identified 17-command modular implant capable of file theft, remote command execution, and in-memory DLL injection.

Rather than standing up dedicated servers, Lazarus routed command-and-control traffic through hijacked Roundcube webmail and WordPress or PrestaShop sites. Many of the compromised Roundcube instances were vulnerable to CVE-2025-49113, a critical PHP deserialization flaw the group exploited using leaked credentials found on the dark web.

These servers hosted RelayShell, a new PHP web shell that relays operator commands to victims through a file-based messaging system rather than executing commands directly, making the traffic blend into normal web activity.

Check Point identified at least 17 unique compromised relay nodes and observed the group connecting through VPN services like ExpressVPN to further mask its origin.

Organizations running Windows 11 builds 26100 or 26200 should prioritize the August Patch Tuesday update to patch CVE-2026-68820, and defense-sector security teams should scrutinize outbound traffic to Roundcube and CMS-hosted infrastructure that may be functioning as covert relay points rather than legitimate mail servers.

IOCs

CategoryIndicatorType
DLL Loader/Dropper2b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca8SHA-256
DLL Loader/Dropper3a02d0d798e8d35555776886d92b20ff38a101c9ef7e0eebc8ce5d259516525aSHA-256
DLL Loader/Dropper92106b0c62a0a42678232f8273f030b2d3c8e92efce81b98b9eec70cfe98afa1SHA-256
DLL Loader/Dropper396192d92d17ace1a521f1351eeeba2825e60badd0d799cc5c338e4934b3c82cSHA-256
DLL Loader/Dropperf7e620134ca935067797ab957317b346ce0df84a4e9b9ca54a6acc9b75afda4dSHA-256
DLL Loader/Dropper75b93a7103b0562f6497d30052c0c5cf7aa58c1bf0e9297022b74469a7f096f1SHA-256
DLL Loader/Droppera45144d22cac70a45d71cf4dffa4efbc373658779a56cf1300d6ac863d6cc7e2SHA-256
DLL Loader/Dropper1de949c71efcfb0ffc41f33d38833dbc4b082075b1a540fc68c18c535d7ad86cSHA-256
DLL Loader/Dropper4c9b804d6155b29f1e27a9ffe531e10bc42a7bdab42f905b50146bf2026768d9SHA-256
DLL Loader/Dropper29e24c007549e51319ff3aee011da6f9f93568e8c85a5ad69c9e53bd3f4533a2SHA-256
DLL Loader/Dropper4ebdce2f47c23ff8c9e8e80c8b5239c7a5764da31cd3ab8f0505926890adc105SHA-256
DLL Loader/Dropperc2aa28bb5e2a749c693712008276f311edd912f689371ef9e8a1ee5fb4167461SHA-256
MISTPEN2db25ac41a66aa523c79e23e00443573530dd7bd82b8371bcc87bd7232e141ebSHA-256
MISTPEN5278ee922838352f1480a73e971161017d643a80b7ec22bf725897dfd088696dSHA-256
MISTPENb4082d21070d9ddf53fde4ea22524d09e41ec9826ce63cef3c6235e458d21afbSHA-256
MISTPENfb3fc5626f68677fb1269a2fefbe70e719211b4065e836ab92e06a8210139a2dSHA-256
MISTPENea7056f2bf36c66a61ff787ff5be975a85f534c3c5ca178791dac2504db2c619SHA-256
MISTPEN13d10bc99f7f7abe7ee0902be87920b73b2ea41bd9683dbfcad340dacbcdef79SHA-256
MISTPEN4fd32432341dfcf54d0517a6bbc38e5d265be70933493e4183c2a340cdde9a2dSHA-256
MISTPEN4dd792c9f672bbdcc8d363d745994efe90f4ffc5fdc2c059c8e379a48ad6a68aSHA-256
MISTPENba96c603e44046de703c67b2c3b7e4ca974afef7b437a0244418bc4edc781bb7SHA-256
ForestTiger72dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289SHA-256
ForestTiger231b1ef8b95bf77887d5377e2a60f649035e78f543af1b82877db36a5759d858SHA-256
ForestTiger6da9b1e6f3315ceb77dd14a937a26cc3602bf6a7e2c2ecafb3c65ce5319837beSHA-256
ForestTigera0578a2b7821d7e2c573530648f26d7a0d98b373ab24fb7f0c792736761e542dSHA-256
ForestTiger82268052f94df6f4870d02e57b18d4c54136cc7a8c8d80ad162631f99462c943SHA-256
FudModule3b6378df8442e63a6ed7317075913e4720847a510d95022d4a8347b2637c245dSHA-256
PDF Payloada673ae661593c0de9bbb815593b816a6853dad6d55ad5042d2ef1875cd13d6e7SHA-256
PDF Payload8ce6c29f92dc45b1474417cbdff4ed0c18e58fa63e3a071ee9f85aa9d2aac07cSHA-256
PDF Payloadacb97cec84e08b89f41967a24e965d1fd2c51751cef158f7aa35bb4306b87b97SHA-256
PDF Payload3601060c62edeeaa49def6a13be6e126e1024ce011faad4e2d9f585ccf6bd5a6SHA-256
PDF Payloadfecf12088843801215898442bd1ff3e266f29d14e29a94780e857f69c4915d6bSHA-256
PDF Payloadd578c28c9afe7457a0d81f6701332ef8197e8f7468de654935fb29a50ea66459SHA-256
SecurityPDF.exe743172aab606974b054a64561534ae66baa3a840657f79d7c6fa18350e8d45d1SHA-256
SecurityPDF.exedb3d69b7eeda2e35e23006bf4b7e206281fce809584207214fc213f9bc30376dSHA-256
Troy Backdoor590fb6ae19480d694e08ee85859cad8066f2f87e7e5abba2960c6d115e1615d6SHA-256
Troy Backdoor68d4fba7b1300a59cd6212c08910a260cd71b40cd9f51cac933030a68faac0bbSHA-256
Troy Backdoora738059ce07c951c31ab2da3d93d8f69bff32f9b7d933dbf5943441b9cc99075SHA-256
RelayShell21c3ad4838c4324bc5f081021da5fb2e9073d0c9304087811c21eb47c9e22762SHA-256
RelayShellcc4e06aa378a190f71384c03023bb3d18a6d66e297d46701220e132963d2e222SHA-256
SecurityPDF Website & Troy C2envell[.]xyzDomain
SecurityPDF Website & Troy C2enveil[.]onlineDomain
SecurityPDF Website & Troy C2uxtramine[.]orgDomain
SecurityPDF Website & Troy C2135.181.67[.]203IP address
SecurityPDF Website & Troy C2135.181.185[.]158IP address

[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

32 minutes ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

10 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

11 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

12 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

12 hours ago