Security & Risk6 minNewsroom

Windows AFD.sys Zero-Day Disables 94 Monitoring Channels, Bringing Lazarus to the Heart of European Defense

Sala de operações de segurança à noite com mapa iluminado de Europa e América do Sul e analista solitário observando dashboard de EDR congelado em alerta

A Check Point Research report published on the 17th details the Troy backdoor and the FudModule rootkit used to silence EDRs in aviation and defense companies in France, Germany, India, and Brazil.

Check Point Research released a comprehensive report on Monday regarding the new wave of the Dream Job Operation, a North Korean espionage scheme that now uses fake job offers to install an unprecedented backdoor called Troy and exploit the vulnerability CVE-2026-68820 in the Windows AFD.sys driver. The report closes a five-week window in which the Lazarus group operated before Microsoft applied the patch on August 11.


CVE-2026-68820 is a use-after-free in the Ancillary Function Driver for WinSock. The CVSS score is 7.0 because the attacker needs code already running on the machine, but the practical effect is an immediate escalation to SYSTEM. Once in SYSTEM, Lazarus loads FudModule in memory, a kernel-mode rootkit that Check Point claims has disabled 94 security telemetry channels at once. This is the number of interest to the CISO: an EDR without a channel does not see the attacker.


How the Offensive Works Internally


The victim receives a recruiter message via LinkedIn, with a position and salary commensurate with their career. The attachment is an encrypted PDF that only opens in SecurityPDF, a trojanized reader distributed by Lazarus itself. By installing the reader, the target triggers the chain: first, the MISTPEN loader ensures persistence, then the local escalation module triggers CVE-2026-68820, and finally, Troy is written to disk. According to Check Point, Troy is a unique DLL capable of network reconnaissance, credential collection, remote execution, and disabling EDR channels.


The command and control does not come from Lazarus's own infrastructure. The group compromised at least 17 relay nodes in vulnerable Roundcube Webmail and WordPress installations, many of which are still exposed to CVE-2025-49113 disclosed in 2025. Malicious traffic leaves the victim disguised as a normal HTTP request to an email server of a small French company that has been previously compromised; nothing in the proxy log alerts the SOC.


The Targets and the Geographic Map


The campaign, active since July, has targeted aviation and aerospace contractors in France, Germany, India, and Brazil, according to Security Affairs confirmed based on Check Point's indicators of compromise. A compromised French company was repurposed as a launch point for spear phishing against third parties, increasing the damage surface without Lazarus needing to renew its infrastructure.


In India, the natural target is the aerospace hubs in Bengaluru and Hyderabad, where HAL and subsidiary integrators exchange code and projects with Western clients. In Brazil, Embraer and its supply chain in São José dos Campos and Botucatu operate with engineering integrated into American and European contractors, making any local senior engineer a target of interest. Check Point did not name the victims, but the mentioned sectors are consistent with the operation of defense and aviation firms in these hubs.


What Changes for the CISO on Tuesday Morning


The Microsoft patch has been available since August 11; any environment with a delay greater than seven days in applying the August KB is exposed. The technical recommendation from Check Point is to accompany the patch with a detection rule for loading unique DLLs in non-standard corporate PDF reader processes, and to tighten the policy on downloading third-party utilities. According to Sergey Shykevich, head of the Check Point Threat Intelligence group, Lazarus will continue to use LinkedIn as an entry vector, and the only filter that works is the internal recruitment process, not the tool.


Eva Chen, CEO of Trend Micro, told Reuters this month that the proportion of attacks using kernel-mode rootkits has more than doubled since the beginning of the year. Trend advocates that the correct response is to migrate telemetry out of the kernel, focusing on observability from the hypervisor. The counter-argument, made by Mandiant analysts in the same report, is that the operational cost of this migration is still higher than the estimated damage. For the detection head of a Brazilian integrator that serves Embraer and a second client in the aerospace sector, who spoke on condition of anonymity, the most urgent task on Tuesday is to audit the list of PDFs downloaded by senior engineers in the past six weeks and compare hashes with the indicators of compromise published by Check Point. It is a manual task that takes three days for a response analyst, but it is the filter that distinguishes who was merely a target from who was a victim. The Lazarus campaign does not dismantle with a patch; it dismantles with process.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk