Adversary Intelligence — 2026-08-16

Lazarus Group Exploits New Windows Zero-Day to Deploy FudModule Rootkit Against Defense Targets

BLUFLazarus Group's modular delivery architecture and durable relay infrastructure ensure that patching CVE-2026-68820 alone leaves compromised defense and aerospace networks exposed to persistent access.

Check Point Research reported that DPRK-linked Lazarus Group targeted defense, aerospace, and aviation firms in Europe, India, and Brazil, with confirmed compromises in France and Germany, in a new wave of its Operation Dream Job campaign 123. Posing as recruiters, the group used sideloaded and trojanized PDF viewers to exploit a zero-day flaw in the Windows AFD.sys driver, CVE-2026-68820, gaining SYSTEM privileges via a loader that used post-quantum Kyber/ML-KEM key exchange to deploy an updated FudModule rootkit that disables EDR telemetry and Smart App Control 13. Check Point confirmed at least 12 exploitation instances and identified a newly documented backdoor, Troy, which supports 17 operator commands and was deployed alongside the known ForestTiger backdoor 14. Microsoft patched the flaw on August 11 1, and Check Point separately found the group compromised at least 17 Roundcube webmail servers by exploiting a distinct flaw, CVE-2025-49113, to deploy a PHP webshell, RelayShell, that relays command-and-control traffic, findings also reported by BleepingComputer 13.

Analysis
Check Point identifies a third-generation Lazarus loader embedding the AFD.sys exploit in a modular framework, MISTPEN, that retains reconnaissance and LPE plug-in capability, so Microsoft's August 11 patch closes one entry point without addressing the delivery architecture. The Troy backdoor and RelayShell webshell extend the group's infrastructure onto compromised Roundcube and WordPress servers, giving it relay capacity independent of any single vulnerability, though the CVE's inclusion in CISA's KEV catalog and the patch suggest the disclosure now functions mainly as retrospective attribution rather than an active unpatched threat window. Findings rest on a single primary source, Check Point, with only secondary amplification elsewhere. Defense, aerospace, and aviation organizations contacted via Dream Job-style recruiting before August 11 should treat FudModule, ForestTiger, or Troy indicators as evidence of prior SYSTEM-level compromise regardless of current patch status.
4 sources
  1. Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack - Check Point Research
  2. Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor - The Hacker News
  3. Lazarus hackers exploited Windows zero-day to target defense firms - BleepingComputer
  4. Lazarus Group Exploits Windows Zero-Day in Backdoor Campaign - DPRK Cyber Threat - News4Hackers

View in full brief →

UNCLASSIFIED // OPEN SOURCE