CVE Tools
Back to feed
Exploited in the wild Windows Lazarus Group nation-state AFD.sys Microsoft

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

Check Point Research has attributed the exploitation of CVE-2026-68820 to the Lazarus Group, a North Korean state-sponsored threat actor targeting defense and aerospace firms in France, Germany, Brazil, and India. This privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) allows attackers to gain SYSTEM-level control, enabling them to deploy the ForestTiger backdoor and evade detection via Smart App Control manipulation.

The campaign, part of the ongoing 'Dream Job' operation, lures victims with fraudulent job offers to install trojanized PDF viewers or malicious DLLs. These payloads execute MISTPEN modules to harvest system information and trigger the AFD.sys exploit. Organizations should immediately apply the fixes released in Microsoft's August 2026 Patch Tuesday updates and monitor for suspicious activity associated with compromised web infrastructure.