Lazarus Group Exploits Windows Vulnerability Four Times in Three Years
North Korea's Lazarus Group has been exploiting a vulnerability in Microsoft's Windows Ancillary Function Driver for WinSock, or afd.sys, since at least 2022. The group has successfully used this driver to gain access to defense sector workers' systems on four separate occasions.
The latest exploitation, CVE-2026-68820, was patched by Microsoft as part of its August 2026 Patch Tuesday release. This vulnerability allows an attacker to trigger a use-after-free race condition in the afd.sys driver, granting them complete system control without requiring elevated privileges.
Check Point Research attributed the exploitation to Lazarus Group, confirming that it was used to install FudModule v3.1 against defense sector targets in France, Germany, Brazil, and India.
The researchers also found that the same driver has been exploited multiple times before, with CVE-2025-21418, CVE-2025-32709, and CVE-2024-38193 all being patched in previous Patch Tuesday releases. This pattern suggests that North Korea has made a sustained research investment into this specific attack surface.