Crypto Ticker:
sysadmin from Cyber Security News

Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit

Guru Baran
9 hours ago
11 Views
0 Comments
Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit

North Korea’s Lazarus group has been caught exploiting a Windows kernel 0-day vulnerability to deploy an upgraded version of its notorious FudModule rootkit, according to new research from Check Point Research. The flaw, now tracked as CVE-2026-68820, lives inside AFD.sys, the Ancillary Function Driver that manages network sockets deep within the Windows kernel. Microsoft patched the bug on August 11 as part of its August Patch Tuesday release, just days after Check Point’s responsible disclosure. The discovery is part of a broader investigation into a fresh wave of Operation Dream Job, a long-running espionage campaign Check Point has tracked since early 2026. This latest iteration zeroes in on the defense, aerospace,...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!