North Korean state hackers exploited an unpatched Windows kernel flaw for five weeks to plant rootkits inside aerospace and defense networks across four countries.
Intelligence Lead
North Korea's Lazarus Group incorporated a Windows kernel zero-day into its long-running Operation Dream Job espionage campaign, gaining SYSTEM-level access on machines belonging to defense, aerospace, and aviation professionals in France, Germany, Brazil, and India. The exploit chain, active for at least five weeks before Microsoft patched it, disabled 94 security-monitoring channels via a FudModule rootkit variant, giving Pyongyang-aligned operators effectively invisible persistence inside contractor networks tied to firms including Lockheed Martin and Enveil.
Situation Report
Check Point Research confirmed that Lazarus exploited CVE-2026-68820, a use-after-free race condition in afd.sys, the Windows Ancillary Function Driver for WinSock that manages network socket operations across virtually every Windows application. Microsoft credited Check Point researchers Moshe Marelus and David Driker with the discovery and patched the flaw on August 11 as part of its August Patch Tuesday release, which addressed 421 vulnerabilities in total. CVE-2026-68820 was the only one of three zero-days in that release confirmed as already exploited in the wild.
Check Point assesses the exploitation began by early July 2026, giving the operation roughly five weeks of unpatched access before remediation. Operators approached targets through fraudulent recruiter outreach on LinkedIn and similar platforms, a tactic that has defined Operation Dream Job since it was first documented in 2020. Victims were induced to open a modified PDF viewer, tracked as SecurityPDF, which deployed an initial backdoor named Troy. Troy in turn delivered ForestTiger, a backdoor family with a well-documented attribution history to Lazarus.
Once resident, the CVE-2026-68820 exploit escalated privileges to SYSTEM level and loaded a new FudModule rootkit variant, killing dozens of endpoint detection and response channels to blind defenders. Reporting from BleepingComputer, The Hacker News, and SecurityAffairs corroborates the Check Point findings and confirms the four-country victim set spans defense contractors, aerospace engineering firms, and aviation-sector organizations.
Background & Context
Operation Dream Job is one of Lazarus Group's most durable espionage tools, running continuously since at least 2020 and repeatedly refreshed with new lure documents, malware families, and exploitation techniques while retaining its core social-engineering premise: a fabricated job offer from a recognizable defense or technology brand. The campaign has previously been linked to intrusions against aerospace, cryptocurrency, and defense-sector targets across multiple continents, consistent with North Korea's dual intelligence-collection and hard-currency objectives.
The afd.sys driver's centrality to Windows networking makes it an unusually high-value target. A working exploit against it grants broad reach across nearly any Windows endpoint, which likely explains why Lazarus invested in weaponizing a kernel-level zero-day rather than relying solely on social engineering and commodity malware, as earlier waves of the campaign have done.
Analysis & Assessment
This operation reflects a maturing pattern in Lazarus tradecraft: pairing a well-worn social-engineering vector with increasingly sophisticated kernel-level exploitation, rather than treating the two as separate lines of effort. It is assessed with high confidence, based on corroborating technical attribution from Check Point and Microsoft, that Lazarus subunits maintain an active zero-day development or acquisition capability specifically aimed at defense-industrial targets, not opportunistic or purely financially motivated victims.
The five-week exploitation window before detection and patching is a significant intelligence failure indicator on the defensive side and suggests North Korean operators calibrate their intrusion timelines to extract maximum value before a patch cycle closes the window. The geographic spread — France, Germany, Brazil, and India — indicates the operation is not regionally confined but targets defense-industrial base nodes wherever aerospace and defense supply chains extend, a pattern consistent with North Korea's interest in weapons and dual-use technology intelligence rather than a specific bilateral dispute.