Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The Lazarus Group has integrated the ML-KEM (Kyber) algorithm into the command-and-control channel of its MISTPEN infrastructure to deliver the CVE-2026-68820 zero-day exploit against the Windows AFD.sys kernel driver. The operation, documented by Check Point Research on August 11, 2026, targeted defense and aerospace companies in Europe and India through the Operation Dream Job campaign. This is not a quantum weapon: it is the first time an APT has adopted NIST-standardized post-quantum cryptography not to defend against quantum computing, but to render its own offensive traffic opaque to current inspection tools.
- ML-KEM (Kyber) encrypts the MISTPEN C2 channel before delivery of the CVE-2026-68820 zero-day exploit
- The vulnerability is a use-after-free with a race condition in the AFD.sys kernel-mode driver, rated CVSS 7.0 by Microsoft
- FudModule v3.1 disables 94 ETW providers and manipulates Smart App Control to evade monitoring
- The exploit was active in-the-wild from at least July 7, 2026, yielding a five-week exploitation window before the August 11 patch
The ML-KEM Mechanism: When Post-Quantum Defense Becomes an Offensive Weapon
The technical innovation resides in MISTPEN's LPE (Local Privilege Escalation) module. The loader requests four public keys from the command-and-control server, generates fresh key material via Kyber/ML-KEM, and returns the encapsulated result. Only after this handshake does the server transmit the encrypted exploit, which is decrypted in memory and executed. This layer overlays the pre-existing GOST-CBC and AES encryption of the MISTPEN framework, making the payload effectively opaque to any system lacking ML-KEM decapsulation capabilities.
Check Point Research documented the full chain: the LPE module obtains the keys, establishes the secure channel, receives the exploit for CVE-2026-68820, and executes it to elevate privileges to SYSTEM. At that point, FudModule v3.1 assumes control of the kernel. The choice of ML-KEM is deliberate: the algorithm is public, standardized by NIST, and its presence in traffic does not trigger particular attention in detection systems. The practical effect is that a technology designed to protect legitimate traffic from future quantum computing is used to protect malicious traffic from the present.
CVE-2026-68820: The Fourth Time AFD.sys Becomes a Zero-Day
The vulnerability is classified by Microsoft as a use-after-free in the Windows Ancillary Function Driver for WinSock. Exploitation requires winning a race condition and assumes local access with limited privileges: the official CVSS is 7.0 (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H), rated HIGH. While technically accurate for the attack model, analysts consider the score underestimated for an actively exploited zero-day against critical infrastructure.
Microsoft assigned the CVE on August 5, 2026, and released the patch on August 11. Check Point had reported the vulnerability on July 28. However, the FudModule v3.1 artifact timestamp dates to July 7, confirming at least five weeks of activity before the fix. Sergey Shykevich, director of threat intelligence at Check Point Software, told The Hacker News the exploit was already functional "in early June," extending the exploitation window to roughly two months.
This is the fourth documented zero-day vulnerability in AFD.sys since 2022, following CVE-2024-38193, CVE-2025-21418, and CVE-2025-32709. The pattern suggests the driver remains a privileged target for kernel-level privilege escalation.
FudModule v3.1, Troy, and RelayShell: The Hidden Infrastructure Behind Legitimacy
Once SYSTEM is obtained, FudModule v3.1 operates directly on kernel structures. Check Point verified that the rootkit disables 94 Event Tracing for Windows (ETW) providers by zeroing EtwpActiveSystemLoggers and global REGHANDLE variables. Simultaneously, it manipulates Smart App Control by setting VerifiedAndReputablePolicyState to zero and invoking NtSetSystemInformation with class 0xA4 and option 0x10000000, forcing an in-place reload of the code integrity policy.
The initial access chain articulates through Operation Dream Job, the social engineering campaign on LinkedIn using fake job offers. Victims are directed to sites impersonating Enveil, a real cybersecurity company, with at least three domains identified: envell[.]xyz, enveil[.]online, uxtramine[.]org. Some of these sites ranked in top search engine results. From there, SecurityPDF, a malicious file that initiates the compromise, is delivered.
The command-and-control infrastructure leverages compromised Roundcube servers via CVE-2025-49113 (CVSS 9.9 CRITICAL), a webmail vulnerability for which Microsoft has already released an advisory. RelayShell, a previously undocumented PHP webshell, was installed on these servers. Check Point identified at least 17 compromised relay servers. In parallel, the Troy backdoor supports 17 operator commands for file enumeration, upload/download, archiving, exfiltration, interactive shell, process termination, in-memory DLL injection, and configuration updates.
"When the website, the download and the recruiter all appear authentic, the old advice to 'spot the phishing link' is no longer easily applicable" — Sergey Shykevich, Check Point Software
What to Do Now
Apply the Microsoft patch for CVE-2026-68820 immediately, added to the CISA KEV catalog on August 11, 2026. The vulnerability is actively exploited and requires no user interaction beyond initial local access.
Verify software through official channels, not search engine rankings. The fake Enveil sites demonstrate that first-page visibility does not equal authenticity.
Inspect MISTPEN traffic on Microsoft Graph API and OneDrive, legitimate channels Lazarus uses for C2. The presence of ML-KEM makes payload inspection impossible without decapsulation, but API access patterns remain analyzable.
Reallocate threat hunting resources to the 94 ETW providers FudModule can disable, with particular attention to Smart App Control policy reload events via NtSetSystemInformation class 0xA4.
Why the ML-KEM Choice Changes the Defense Perimeter
Lazarus's adoption of post-quantum cryptography is not a technical curiosity: it is a strategic anticipation of the problem CISOs will face in the coming years. Current monitoring architectures assume C2 traffic is, in principle, inspectable. ML-KEM renders that premise obsolete without waiting for quantum computers to become available. The dossier does not specify how the group obtained the four initial public keys for the handshake, nor whether the use of ML-KEM is motivated by a specific known threat to its operators. No infrastructure overlaps linking this exploit to other APT groups have emerged to date.
The operation hits companies in France, Germany, Brazil, and India, with a focus on surveillance sensors, drones, and robotics. The targets mirror Lazarus's historical pattern in the UAV sector documented by ESET. The persistence of the social engineering vector through LinkedIn, despite years of awareness campaigns, confirms that targeted social engineering remains the cheapest and most effective entry point.
Information verified against cited sources and current as of publication.
Sources
- https://www.infosecurity-magazine.com/news/lazarus-post-quantum-key-dream-job/
- https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
- https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html
- https://www.ibtimes.co.uk/lazarus-group-exploits-windows-flaw-quantum-encryption-1814104
- https://www.webpronews.com/microsofts-august-2026-patches-close-421-holes-as-north-korean-hackers-turn-kernel-driver-into-zero-day-weapon/
- https://www.techtimes.com/articles/324157/20260812/lazarus-group-hacked-defense-workers-windows-kernel-zero-day-five-weeks.htm
- https://finance.biggo.com/news/3518b7b4-5d6d-4381-aa34-a1a3685ea695
- https://www.techtimes.com/articles/324204/20260812/north-korea-hacked-defense-firms-four-times-via-same-windows-driver-patch-now.htm
- https://nvd.nist.gov/vuln/detail/cve-2025-49113
- https://www.welivesecurity.com/en/eset-research/gotta-fly-lazarus-targets-uav-sector/
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.