Check Point Research disclosed on 12 August 2026 that the Lazarus Group had been exploiting CVE-2026-68820, a use-after-free race condition in AFD.sys — the Windows ancillary function driver for WinSock — to escalate to SYSTEM. The flaw carries a CVSS score of 7.0. Check Point reported it to Microsoft on 28 July; Microsoft shipped a fix on 11 August. Exploitation is traced to early July, giving roughly five weeks in the wild.
The campaign is the long-running Operation Dream Job: fake employment approaches to people working in defence, aerospace, aviation, drone, robotics and military technology, with activity reported in France, Germany, Brazil and India. One chain delivered a ZIP containing a legitimate PDF viewer alongside a malicious DLL; another used a search-optimised site impersonating a real privacy technology company. Both led to MISTPEN, an in-memory downloader, which ran reconnaissance, established persistence, loaded the privilege escalation module and then deployed FudModule v3.1, a kernel-mode rootkit.
The command channel negotiated keys using Kyber — ML-KEM — with a further GOST-CBC layer, and moved traffic through attacker-controlled files on OneDrive via the Microsoft Graph API.
There Is No Such Thing As Quantum-Grade Encryption
The phrase has attached itself to this story and it does not describe anything. ML-KEM is not stronger than what it replaces against any computer that exists. It is designed to resist a machine nobody has built.
Using it in a command channel therefore buys the attacker nothing today. What it buys is protection against a defender who captures the traffic now and decrypts it later — the harvest-now-decrypt-later problem, turned around and pointed at the people doing the recording. Network capture is one of the few durable artefacts an investigator gets; this is an operation deciding that its 2026 traffic should still be unreadable in 2040.
The Migration Cost Is Wildly Asymmetric
This corpus filed the defender’s side twice this year. At 26-0427 NIST finalised ML-KEM, ML-DSA and SLH-DSA with migration deadlines beginning September 2026, and the desk noted the hard part was never the mathematics. At 26-0514 the global migration was costed at around $15 billion, almost none of it cryptography — it is finding and replacing things.
For an adversary writing new malware, adopting ML-KEM is one library and a compile. There is no inventory, no legacy protocol, no embedded device with a fifteen-year service life, no vendor to wait for, no change board. A defence contractor faces every one of those. The result recorded here is an attacker that has completed a transition its targets have barely begun, and the reason is not sophistication — it is that greenfield is cheap and estates are not.
The Escalation Exists To Blind The Sensor
The zero-day’s purpose is narrow. SYSTEM privileges let FudModule reach kernel data structures and strip out the security product registrations and logging pipelines that endpoint detection depends on.
That is worth stating plainly against the audit at 26-0802, where 251 files establish no entry route. This is a mechanism for producing exactly that outcome: the intrusion is not merely undetected, the instrument that would have recorded it has been switched off from underneath. Where a corpus file says the route was never established, this is one of the reasons why.
A CVSS Of 7.0 On The Thing That Owns The Kernel
The flaw scores 7.0 — high, not critical — because it requires local access and wins a race condition. Both are true and neither constrains this operation, which already has code running and only needs privilege.
Reporting notes this is the fourth time North Korean activity has been tied to this same driver. We have recorded the same longitudinal pattern at 24-1031, where one vendor documented five years of intrusions against a single product line. A component that is present on every Windows machine, sits in the kernel and handles sockets will keep being worth the research budget however any individual bug is scored.
The Lure Was A Job
Underneath the kernel exploit and the post-quantum key exchange, the way in was an approach about employment made to an engineer who works on drones or sensors.
We keep arriving at this. At 22-0324 the people who reached Okta and Microsoft were teenagers with a telephone; at 25-0810 the best-resourced organisation in this database was reached by a conversation. Considering a job offer is not a lapse. It is the one approach that reliably gets a careful person to open a file, and no control in the stack engages with it.
Compiled from Check Point Research’s published analysis and on independent reporting of it, listed below. This file was suggested from an aggregator write-up; the desk went to the originating research instead, for the reason recorded at 25-0421b — a summary of a report is not the report. Attribution to the Lazarus Group and to North Korea is the researchers’ assessment and is carried as such; this desk attributes nothing to any state. Reporting describes a real privacy technology company, Enveil, as impersonated by a lure site — Check Point stated it was neither targeted nor compromised, and that is recorded here so the association is not left hanging. The count of prior North Korean activity involving this driver is as reported and has not been independently enumerated by this desk. No indicators, samples or exploit detail are reproduced. Corrections: corrections@forensicpost.com.
- Shattering the Dream — When a Job Offer Becomes a Zero-Day AttackCheck Point Research
- Lazarus hackers exploited Windows zero-day to target defense firmsBleepingComputer
- Lazarus Used Post-Quantum Key Exchange to Deliver Zero-DayInfosecurity Magazine