Future TechnologyFuture Technology
NEWS

Lazarus used a Windows zero-day to drop a kernel rootkit on aerospace firms

· 2 min read · By Future Technology

Key takeaways

  • CVE-2026-68820 is an elevation of privilege flaw in the Windows Ancillary Function Driver for WinSock, handing a locally authenticated attacker SYSTEM privileges with no user interaction
  • Lazarus used it to install a new build of the FudModule kernel-mode rootkit against defence, aerospace and aviation firms in Europe, India and Brazil
  • A separate SAP Commerce Cloud flaw, CVE-2026-58231, carries a perfect 10.0 CVSS score and is already seeing exploitation attempts

A recruiter messages an engineer at an aerospace firm about a role. There is a PDF attached, and a viewer to open it with. That is the whole attack, and it is still working.

CVE-2026-68820 is an elevation of privilege flaw in the Windows Ancillary Function Driver for WinSock, patched in the August update. A locally authenticated attacker triggers a race condition with a crafted application and comes away with SYSTEM privileges. No user interaction is needed once the attacker already has a foothold on the machine, which is why the recruiter lure is the important half of the story.

What Lazarus did with CVE-2026-68820

The North Korean state-linked group deployed the flaw to install a new build of the FudModule kernel-mode rootkit, as part of a fresh wave of Operation Dream Job. Targets were defence, aerospace and aviation firms across Europe, India and Brazil, approached with fake recruiter messages and trojanised PDF viewers.

FudModule is not a smash and grab. A kernel-mode rootkit sits underneath the security tooling meant to spot it, so detection gets harder the longer it stays, and the machine can no longer be trusted to report honestly on itself. On a defence contractor endpoint that is a very long-lived problem.

The other item worth patching this week is CVE-2026-58231 in SAP Commerce Cloud, disclosed on 12 August with a CVSS score of 10.0. Exploitation attempts are already being seen. If you run commerce infrastructure, that one outranks the Windows flaw on urgency.

Why the recruiter lure keeps working

Operation Dream Job has been running in some form for years, and Lazarus keeps returning to it because a job offer is the most normal thing that lands in a skilled engineer inbox. It carries a plausible reason to open an attachment, a plausible reason to keep it quiet, and a plausible reason to reply quickly.

Once that foothold exists, a privilege escalation bug is what converts a user-level compromise into full control of the machine. The same pattern runs through this month 421 patched CVEs, and it is the social-engineering-first shape behind voice phishing campaigns and most of the ransomware activity hitting large companies this year.

What to watch for next

Apply the August update if you have not already. Then treat unsolicited recruiter contact carrying files as the delivery mechanism it has repeatedly turned out to be, particularly if you work anywhere near defence or aviation. Expect the next Dream Job wave to arrive with a different lure and the same structure underneath it.

Get the briefing, free

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.