North Korea’s Lazarus group has been caught exploiting a Windows kernel 0-day vulnerability to deploy an upgraded version of its notorious FudModule rootkit, according to new research from Check Point Research.
The flaw, now tracked as CVE-2026-68820, lives inside AFD.sys, the Ancillary Function Driver that manages network sockets deep within the Windows kernel. Microsoft patched the bug on August 11 as part of its August Patch Tuesday release, just days after Check Point’s responsible disclosure.
The discovery is part of a broader investigation into a fresh wave of Operation Dream Job, a long-running espionage campaign Check Point has tracked since early 2026. This latest iteration zeroes in on the defense, aerospace, and aviation sectors, with confirmed activity across Europe, India, Brazil, and other regions.
The attackers pose as recruiters offering enticing job opportunities, a social engineering trick Lazarus has relied on for years to lure employees at high-value targets into opening malicious files.
Check Point identified two parallel infection chains. The first relies on DLL sideloading, where victims download an encrypted ZIP archive containing a legitimate signed PDF viewer, a malicious DLL named libmupdf.dll, and an encrypted payload disguised with a PDF extension.

Once launched, the sideloaded DLL quietly extracts and decrypts a hidden payload in memory while showing the victim a decoy document, in one case a fake Lockheed Martin job description, to maintain the illusion of legitimacy.
The second chain uses a trojanized PDF viewer called SecurityPDF, built on the open-source MuPDF framework and modified to impersonate Enveil, a privacy technology firm.
The attackers even seeded SEO-optimized impersonation websites that rank highly in search results for terms like “Enveil SecurityPDF,” a tactic that lets them separate delivery of the malicious viewer from the delivery of the booby-trapped PDF and reduces the odds of detection.
Both chains ultimately execute MISTPEN, a lightweight in-memory downloader first documented by Mandiant in 2024. MISTPEN abuses the Microsoft Graph API to pull additional modules from attacker-controlled OneDrive storage, encrypting all traffic with AES.
It first deploys reconnaissance and screenshot modules to profile the victim machine, then, once the target is validated, delivers a privilege-escalation module that triggers the AFD.sys exploit.
Successful exploitation of CVE-2026-68820 hands the attackers SYSTEM-level privileges and launches FudModule, Lazarus’s signature kernel-mode rootkit first seen around 2021 and previously linked to a separate AFD.sys use-after-free bug, CVE-2024-38193.
The new variant, which Check Point labels FudModule v3.1, retains most of the rootkit’s core sabotage toolkit: it strips telemetry callbacks, disables minifilters, kills the NT Kernel Logger, and blinds over 90 ETW providers using a kill-list nearly identical to previous versions.
Notably, it drops the dedicated Microsoft Defender-disabling routine used in earlier releases and instead blinds security products through a generic suppression engine. It also adds a new capability to tamper with Smart App Control by resetting its verified-and-reputable policy state.
Once elevated, FudModule injects a fresh MISTPEN instance into a SYSTEM process, letting the attackers operate invisibly to most EDR tools before deploying ForestTiger, a long-documented Lazarus backdoor, or Troy, a newly identified 17-command modular implant capable of file theft, remote command execution, and in-memory DLL injection.
Rather than standing up dedicated servers, Lazarus routed command-and-control traffic through hijacked Roundcube webmail and WordPress or PrestaShop sites. Many of the compromised Roundcube instances were vulnerable to CVE-2025-49113, a critical PHP deserialization flaw the group exploited using leaked credentials found on the dark web.
These servers hosted RelayShell, a new PHP web shell that relays operator commands to victims through a file-based messaging system rather than executing commands directly, making the traffic blend into normal web activity.
Check Point identified at least 17 unique compromised relay nodes and observed the group connecting through VPN services like ExpressVPN to further mask its origin.
Organizations running Windows 11 builds 26100 or 26200 should prioritize the August Patch Tuesday update to patch CVE-2026-68820, and defense-sector security teams should scrutinize outbound traffic to Roundcube and CMS-hosted infrastructure that may be functioning as covert relay points rather than legitimate mail servers.
| Category | Indicator | Type |
|---|---|---|
| DLL Loader/Dropper | 2b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca8 | SHA-256 |
| DLL Loader/Dropper | 3a02d0d798e8d35555776886d92b20ff38a101c9ef7e0eebc8ce5d259516525a | SHA-256 |
| DLL Loader/Dropper | 92106b0c62a0a42678232f8273f030b2d3c8e92efce81b98b9eec70cfe98afa1 | SHA-256 |
| DLL Loader/Dropper | 396192d92d17ace1a521f1351eeeba2825e60badd0d799cc5c338e4934b3c82c | SHA-256 |
| DLL Loader/Dropper | f7e620134ca935067797ab957317b346ce0df84a4e9b9ca54a6acc9b75afda4d | SHA-256 |
| DLL Loader/Dropper | 75b93a7103b0562f6497d30052c0c5cf7aa58c1bf0e9297022b74469a7f096f1 | SHA-256 |
| DLL Loader/Dropper | a45144d22cac70a45d71cf4dffa4efbc373658779a56cf1300d6ac863d6cc7e2 | SHA-256 |
| DLL Loader/Dropper | 1de949c71efcfb0ffc41f33d38833dbc4b082075b1a540fc68c18c535d7ad86c | SHA-256 |
| DLL Loader/Dropper | 4c9b804d6155b29f1e27a9ffe531e10bc42a7bdab42f905b50146bf2026768d9 | SHA-256 |
| DLL Loader/Dropper | 29e24c007549e51319ff3aee011da6f9f93568e8c85a5ad69c9e53bd3f4533a2 | SHA-256 |
| DLL Loader/Dropper | 4ebdce2f47c23ff8c9e8e80c8b5239c7a5764da31cd3ab8f0505926890adc105 | SHA-256 |
| DLL Loader/Dropper | c2aa28bb5e2a749c693712008276f311edd912f689371ef9e8a1ee5fb4167461 | SHA-256 |
| MISTPEN | 2db25ac41a66aa523c79e23e00443573530dd7bd82b8371bcc87bd7232e141eb | SHA-256 |
| MISTPEN | 5278ee922838352f1480a73e971161017d643a80b7ec22bf725897dfd088696d | SHA-256 |
| MISTPEN | b4082d21070d9ddf53fde4ea22524d09e41ec9826ce63cef3c6235e458d21afb | SHA-256 |
| MISTPEN | fb3fc5626f68677fb1269a2fefbe70e719211b4065e836ab92e06a8210139a2d | SHA-256 |
| MISTPEN | ea7056f2bf36c66a61ff787ff5be975a85f534c3c5ca178791dac2504db2c619 | SHA-256 |
| MISTPEN | 13d10bc99f7f7abe7ee0902be87920b73b2ea41bd9683dbfcad340dacbcdef79 | SHA-256 |
| MISTPEN | 4fd32432341dfcf54d0517a6bbc38e5d265be70933493e4183c2a340cdde9a2d | SHA-256 |
| MISTPEN | 4dd792c9f672bbdcc8d363d745994efe90f4ffc5fdc2c059c8e379a48ad6a68a | SHA-256 |
| MISTPEN | ba96c603e44046de703c67b2c3b7e4ca974afef7b437a0244418bc4edc781bb7 | SHA-256 |
| ForestTiger | 72dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289 | SHA-256 |
| ForestTiger | 231b1ef8b95bf77887d5377e2a60f649035e78f543af1b82877db36a5759d858 | SHA-256 |
| ForestTiger | 6da9b1e6f3315ceb77dd14a937a26cc3602bf6a7e2c2ecafb3c65ce5319837be | SHA-256 |
| ForestTiger | a0578a2b7821d7e2c573530648f26d7a0d98b373ab24fb7f0c792736761e542d | SHA-256 |
| ForestTiger | 82268052f94df6f4870d02e57b18d4c54136cc7a8c8d80ad162631f99462c943 | SHA-256 |
| FudModule | 3b6378df8442e63a6ed7317075913e4720847a510d95022d4a8347b2637c245d | SHA-256 |
| PDF Payload | a673ae661593c0de9bbb815593b816a6853dad6d55ad5042d2ef1875cd13d6e7 | SHA-256 |
| PDF Payload | 8ce6c29f92dc45b1474417cbdff4ed0c18e58fa63e3a071ee9f85aa9d2aac07c | SHA-256 |
| PDF Payload | acb97cec84e08b89f41967a24e965d1fd2c51751cef158f7aa35bb4306b87b97 | SHA-256 |
| PDF Payload | 3601060c62edeeaa49def6a13be6e126e1024ce011faad4e2d9f585ccf6bd5a6 | SHA-256 |
| PDF Payload | fecf12088843801215898442bd1ff3e266f29d14e29a94780e857f69c4915d6b | SHA-256 |
| PDF Payload | d578c28c9afe7457a0d81f6701332ef8197e8f7468de654935fb29a50ea66459 | SHA-256 |
| SecurityPDF.exe | 743172aab606974b054a64561534ae66baa3a840657f79d7c6fa18350e8d45d1 | SHA-256 |
| SecurityPDF.exe | db3d69b7eeda2e35e23006bf4b7e206281fce809584207214fc213f9bc30376d | SHA-256 |
| Troy Backdoor | 590fb6ae19480d694e08ee85859cad8066f2f87e7e5abba2960c6d115e1615d6 | SHA-256 |
| Troy Backdoor | 68d4fba7b1300a59cd6212c08910a260cd71b40cd9f51cac933030a68faac0bb | SHA-256 |
| Troy Backdoor | a738059ce07c951c31ab2da3d93d8f69bff32f9b7d933dbf5943441b9cc99075 | SHA-256 |
| RelayShell | 21c3ad4838c4324bc5f081021da5fb2e9073d0c9304087811c21eb47c9e22762 | SHA-256 |
| RelayShell | cc4e06aa378a190f71384c03023bb3d18a6d66e297d46701220e132963d2e222 | SHA-256 |
| SecurityPDF Website & Troy C2 | envell[.]xyz | Domain |
| SecurityPDF Website & Troy C2 | enveil[.]online | Domain |
| SecurityPDF Website & Troy C2 | uxtramine[.]org | Domain |
| SecurityPDF Website & Troy C2 | 135.181.67[.]203 | IP address |
| SecurityPDF Website & Troy C2 | 135.181.185[.]158 | IP address |