Nation-State Threats - 6 min read - 16 August 2026

A fake LinkedIn recruiter got Lazarus a Windows kernel zero-day. It ran for five weeks before Patch Tuesday caught up.

Check Point Research says the North Korea-linked Lazarus group used a Windows kernel driver flaw to plant its FudModule rootkit on defence and aerospace targets in Europe and India, starting with nothing more sophisticated than a message from a fake recruiter. Microsoft fixed the flaw on 11 August, five weeks after Lazarus started using it.

The entry point for this campaign wasn't a phishing kit or an exposed server, it was a LinkedIn message from someone who appeared to be recruiting for Lockheed Martin or Enveil. That detail alone would make this a routine writeup of Operation Dream Job, the years-old Lazarus playbook of posing as a defence-sector recruiter to get a foot in the door. What made it worth CISA's attention this month was what happened after the door opened: a Windows kernel zero-day, tracked as CVE-2026-68820, that let Lazarus turn an ordinary user foothold into full SYSTEM control on target machines, weeks before Microsoft even knew the flaw existed. Check Point Research's disclosure and Bleeping Computer's reporting both trace the same chain: a recruiter lure most security teams have trained staff to recognise, paired with a privilege-escalation flaw nobody could have.

The recruiter pitch hasn't needed to change

Operation Dream Job works on a simple asymmetry: a defence or aerospace employee gets approached by what looks like a genuine recruiter, often referencing a real company or a real open role, and the conversation moves toward a document or a "assessment" file that's actually the delivery mechanism. Researchers observed the latest wave impersonating recruiters tied to Lockheed Martin and Enveil, aimed at organisations in Europe and India. None of that is new tradecraft - it's worked for Lazarus for years precisely because it targets a moment (a job conversation) where people are inclined to open an attachment from a stranger. What's changed is what the payload could do once it landed.

Five weeks between first use and first patch

CVE-2026-68820 sits in afd.sys, the Ancillary Function Driver for WinSock that underpins nearly every networking operation on Windows. It's a use-after-free triggered by a race condition: two threads compete to access socket state without proper synchronisation, and an attacker who wins that race can corrupt freed memory and obtain a kernel read/write primitive - a foothold below the operating system's own protections. It doesn't grant remote access on its own; it needs code already running on the machine, which is exactly what the recruiter lure supplied. From there, it turns a standard user session into full SYSTEM privileges, enough to deploy FudModule, Lazarus's kernel-mode rootkit built specifically to blind security monitoring tools once it's in. A compiled FudModule artefact recovered from the investigation carries a timestamp of 7 July, meaning Lazarus had this capability running against real targets for roughly five weeks before Microsoft shipped a fix as part of its August Patch Tuesday update - a release that landed 421 CVE fixes in total, this one among them. CISA added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog the same day, with a two-week deadline for federal agencies to patch.

A privilege-escalation bug is still worth this much attention

It would be easy to file this under "local-only, needs existing access" and rank it below the fully remote, no-credentials flaws that made this month's KEV additions alongside it, including Cisco's ASA and FTD firewall flaw. That ranking misses what a privilege-escalation zero-day is actually worth to an operator like Lazarus: it's the second half of an attack chain whose first half - social engineering a defence employee into running a file - already works reliably. The zero-day's entire job is converting a foothold that endpoint tools might eventually catch into one that disables the tools first. That's a more dangerous combination than either half alone, and it's the same shape July's record Patch Tuesday was already warning about: identity and endpoint flaws chained together move faster than annual patch cycles assume.

  • Patch CVE-2026-68820 now if you haven't - Microsoft shipped the fix in the 11 August update, and CISA's KEV listing means active exploitation is confirmed, not theoretical.
  • Brief defence, aerospace and any nationally sensitive-sector staff specifically on recruiter-lure tradecraft; Operation Dream Job succeeds on the social engineering step, not on technical sophistication at first contact.
  • Review endpoint detection coverage for gaps a kernel-mode rootkit could exploit - FudModule's entire purpose is disabling the monitoring you're relying on to catch it.
  • Treat privilege-escalation zero-days as seriously as remote ones when they pair with a proven initial-access method; the chain, not the individual CVSS score, is what determines real-world risk.

A five-week head start against a defence-sector target is not a small window. If you need help assessing whether your organisation's patch cadence and endpoint coverage would have caught this chain before Patch Tuesday did, email sales@halfteck.com.

Explore more resources

Browse our full library of enterprise cloud, software, data and AI content.

View all resources