BoletimSecAugust 13, 2026🇵🇹Translated from Portuguese

Lazarus Group Exploits Windows Kernel Zero-Day CVE-2026-68820 to Deploy FudModule Rootkit

The North Korean Lazarus group is actively exploiting a zero-day vulnerability in the Windows kernel to obtain SYSTEM privileges and deploy the FudModule rootkit. The flaw, identified as CVE-2026-68820, was patched by Microsoft on 11 August.

The vulnerability affects afd.sys, the driver that handles network functions and socket management in Windows. Exploitation requires the attacker to already possess the ability to execute code with limited privileges on the target machine. From that position, the bug enables escalation to SYSTEM rights, granting extensive control over the operating system.

The campaign is part of Operation Dream Job, a long-running espionage operation that relies on fabricated job offers aimed at specialists in defense, aerospace, and aviation. Activity has been observed in Brazil, Europe, and India. Targets are lured into opening tampered PDF viewers or specially crafted files.

The attack chain begins with the MISTPEN downloader, which gathers basic system information before delivering the zero-day exploit. After privilege escalation, FudModule interferes with Windows telemetry mechanisms and reduces visibility for EDR solutions. The latest variant can also manipulate Smart App Control to further weaken additional protections.

Organizations are advised to apply the August Windows security updates immediately and to strengthen monitoring of files associated with fake employment opportunities.

Related articles

BoletimSecState-Sponsored & APT

APT28 Expands Espionage with New HOOKEDGE Backdoor Targeting European Organizations

The Russian-linked APT28 group, also known as BlueDelta, has deployed a new lightweight backdoor called HOOKEDGE as part of a cyber-espionage campaign against strategic European entities. The attacks, assessed with moderate confidence, targeted government, diplomatic, and defense manufacturing organizations in Romania, Spain, and Turkey between September 2025 and April 2026. Infection begins with spear-phishing emails delivering Microsoft Word documents containing malicious macros that mimic official Spanish government materials. Upon execution, the macros drop files, establish persistence via scheduled tasks, and deploy the HOOKEDGE backdoor written in batch scripts. The malware uses hidden Microsoft Edge instances and the legitimate webhook.site service to blend command-and-control traffic with normal web activity. In high-value victims, operators installed a second HOOKEDGE instance with five-minute check-ins for faster control and data collection. The backdoor shows strong code similarities to the older HEADLACE implant previously attributed to the same group.

BoletimSecState-Sponsored & APT

Iran-Linked Cyber Attack Leaves Small UK Power Plant Offline for Four Days

A cyber attack attributed to hackers with suspected ties to Iran took a small-scale UK power generation facility offline for approximately four days in July 2026. The incident affected a roughly 15 MW generator used to support peak demand periods, yet caused no customer outages or disruption to the national electricity grid. British authorities have not issued an official attribution, and investigators have not publicly identified the malware, vulnerability, or initial access vector used in the operation. Recovery required four days of extensive validation across controllers, configurations, security systems, and remote access points to ensure no residual risks remained. The case highlights the operational challenges of restoring industrial control environments after suspected nation-state activity. In response, UK authorities have strengthened guidance for the energy sector and are considering additional protective measures for critical infrastructure suppliers.

BoletimSecState-Sponsored & APT

Iran-Linked Tortoiseshell Group Deploys Malicious wtsapi32.dll Backdoor for Persistent Windows Access

Researchers have uncovered new tools deployed by the Tortoiseshell group, an Iranian-linked threat actor also tracked as Mirage Kitten, UNC1549, and Nimbus Manticore. The campaign features a Windows backdoor disguised as the legitimate wtsapi32.dll library that silently establishes reverse SSH tunnels over port 443 to maintain access to compromised networks. Active since at least 2018, the group has targeted defense, aerospace, technology, IT services, and military organizations primarily in the Middle East and the United States. The malware preserves expected Windows API functions while enabling command execution, file exfiltration, in-memory DLL loading, directory listing, and system reconnaissance. Associated infrastructure spans the United Arab Emirates, Saudi Arabia, the United Kingdom, Belgium, Canada, Australia, and Japan.

AntiMalwareState-Sponsored & APT

HoneyMyte APT Deploys Kernel-Level CoolClient Backdoor Disguised as Microsoft Defender

The Chinese-speaking APT group HoneyMyte has deployed an updated version of its CoolClient backdoor in espionage operations targeting government and private organizations in Russia, Myanmar, Mongolia, Pakistan, and India. The new variant operates at the Windows kernel level using a signed driver, allowing it to hide processes, files, registry entries, and network activity while evading detection. Attackers first abuse PlugX to add exclusions for Microsoft Defender, then drop a fake Windows Defender directory containing the renamed Sangfor binary defender.exe and the malicious libngs.dll. A scheduled task ensures persistence by launching the fake defender.exe with high privileges on system startup. Kaspersky GReAT researchers note that the kernel-mode capabilities significantly increase the backdoor’s stealth and survivability compared to its previous user-mode implementation. The campaign demonstrates sophisticated living-off-the-land techniques combined with legitimate software abuse.