Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
A zero-day vulnerability in Windows' Ancillary Function Driver for WinSock (afd.sys), tracked as CVE-2026-68820, has been exploited by North Korean Lazarus Group hackers to gain full system control and deploy the ForestTiger backdoor. The attacks target defense, aerospace, and aviation sectors in multiple countries, including Europe and India, using fake job recruitment lures. The vulnerability is a use-after-free issue allowing privilege escalation to System. Microsoft released a patch on August 11, 2026, and CISA has added it to its Known Exploited Vulnerabilities catalog, urging prompt patching. The campaign also uses a trojanized PDF viewer to deploy the Troy backdoor and compromised webmail and CMS servers as command-and-control infrastructure.
AI Analysis
Technical Summary
The vulnerability CVE-2026-68820 is a use-after-free flaw in Windows afd.sys that enables attackers to trigger a race condition and escalate privileges to System level. North Korean Lazarus Group has exploited this zero-day in a campaign targeting aerospace and defense organizations, primarily in Europe and India, since early 2026. Attackers use social engineering via fake job offers to deliver malicious payloads involving DLL sideloading and malware downloaders. The exploitation chain culminates in deploying the ForestTiger backdoor. Additionally, a trojanized PDF viewer named SecurityPDF is used to deploy the Troy backdoor in memory. The attackers' infrastructure includes compromised Roundcube webmail and CMS platforms vulnerable to CVE-2025-49113, hosting a PHP webshell called RelayShell for command relay. Microsoft patched the vulnerability on August 11, 2026, and CISA has mandated patching within two weeks for federal agencies.
Potential Impact
Successful exploitation allows attackers to gain full System privileges on affected Windows systems, enabling complete control over the victim machine. This facilitates deployment of persistent backdoors such as ForestTiger and Troy, enabling extensive espionage capabilities including file operations, shell access, process manipulation, and data exfiltration. The campaign targets sensitive sectors like defense and aerospace, potentially compromising critical intellectual property and operational security. The use of sophisticated infection chains and web-based command infrastructure increases stealth and persistence.
Mitigation Recommendations
Microsoft released an official patch for CVE-2026-68820 on August 11, 2026, as part of Patch Tuesday updates. Organizations, especially in defense, aerospace, and aviation sectors, should prioritize applying this update immediately. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog and urges federal agencies to patch within two weeks. Security teams should also scrutinize unsolicited recruitment communications and avoid downloading unverified payloads. Reviewing indicators of compromise related to ForestTiger, Troy backdoors, and associated infrastructure is recommended. No vendor advisory indicates that no action is required; patching is the primary mitigation.
Affected Countries
France, Germany, Brazil, India
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
Description
A zero-day vulnerability in Windows' Ancillary Function Driver for WinSock (afd.sys), tracked as CVE-2026-68820, has been exploited by North Korean Lazarus Group hackers to gain full system control and deploy the ForestTiger backdoor. The attacks target defense, aerospace, and aviation sectors in multiple countries, including Europe and India, using fake job recruitment lures. The vulnerability is a use-after-free issue allowing privilege escalation to System. Microsoft released a patch on August 11, 2026, and CISA has added it to its Known Exploited Vulnerabilities catalog, urging prompt patching. The campaign also uses a trojanized PDF viewer to deploy the Troy backdoor and compromised webmail and CMS servers as command-and-control infrastructure.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-68820 is a use-after-free flaw in Windows afd.sys that enables attackers to trigger a race condition and escalate privileges to System level. North Korean Lazarus Group has exploited this zero-day in a campaign targeting aerospace and defense organizations, primarily in Europe and India, since early 2026. Attackers use social engineering via fake job offers to deliver malicious payloads involving DLL sideloading and malware downloaders. The exploitation chain culminates in deploying the ForestTiger backdoor. Additionally, a trojanized PDF viewer named SecurityPDF is used to deploy the Troy backdoor in memory. The attackers' infrastructure includes compromised Roundcube webmail and CMS platforms vulnerable to CVE-2025-49113, hosting a PHP webshell called RelayShell for command relay. Microsoft patched the vulnerability on August 11, 2026, and CISA has mandated patching within two weeks for federal agencies.
Potential Impact
Successful exploitation allows attackers to gain full System privileges on affected Windows systems, enabling complete control over the victim machine. This facilitates deployment of persistent backdoors such as ForestTiger and Troy, enabling extensive espionage capabilities including file operations, shell access, process manipulation, and data exfiltration. The campaign targets sensitive sectors like defense and aerospace, potentially compromising critical intellectual property and operational security. The use of sophisticated infection chains and web-based command infrastructure increases stealth and persistence.
Mitigation Recommendations
Microsoft released an official patch for CVE-2026-68820 on August 11, 2026, as part of Patch Tuesday updates. Organizations, especially in defense, aerospace, and aviation sectors, should prioritize applying this update immediately. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog and urges federal agencies to patch within two weeks. Security teams should also scrutinize unsolicited recruitment communications and avoid downloading unverified payloads. Reviewing indicators of compromise related to ForestTiger, Troy backdoors, and associated infrastructure is recommended. No vendor advisory indicates that no action is required; patching is the primary mitigation.
Technical Details
- Classification
- {"confidence":0.7,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks/","fetched":true,"fetchedAt":"2026-08-12T08:56:13.355Z","wordCount":1190}
Threat ID: 6a7c352dbf8831d5394902b2
Added to database: 08/12/2026, 08:56:13 UTC
Last enriched: 08/12/2026, 08:56:22 UTC
Last updated: 08/12/2026, 09:02:06 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.