
Lazarus Chains CVE-2026-68820 with MISTPEN and FudModule to Deploy Troy Backdoor
Lazarus exploited a patched Windows AFD.sys zero-day to gain SYSTEM access and deploy the Troy backdoor through DLL side-loading and trojanized PDF viewers. Evidence shows reuse of FudModule rootkit and ML-KEM crypto since 2022 operations. The pattern indicates sustained targeting of defense sectors with evolving evasion techniques.
The observed activity used DLL side-loading through a malicious libmupdf.dll that executed MISTPEN, which fetched reconnaissance modules and triggered the AFD.sys local privilege escalation before loading ForestTiger. A second vector deployed a trojanized SecurityPDF viewer that decrypted and injected the Troy backdoor into memory upon detecting a specific marker. Both paths relied on the FudModule rootkit, updated with ML-KEM key exchange, to hide processes from security tools.
Technical indicators align with Lazarus TTPs documented since 2022: repeated AFD.sys targeting, OneDrive C2 via Microsoft Graph, and trojanized PDF viewers first seen in Dream Job waves. Check Point's attribution rests on infrastructure reuse and command sets, yet no independent packet captures or binary hashes have been published to confirm the link beyond behavioral similarity.
The campaign's focus on aerospace and defense contractors, combined with post-quantum cryptography in the loader, signals preparation for longer dwell times against maturing endpoint detection. Expect continued kernel zero-day chaining as Microsoft patch cycles fail to outpace state resource allocation.
Next observed activity will likely include variant infection chains against additional Indian and European contractors within 120 days.
Lazarus: At least three additional defense contractors will report Troy or ForestTiger infections via AFD.sys variants by December 2026.
Sources (2)
- [1]Check Point Research: Operation Dream Job Update(https://research.checkpoint.com/2026/08/lazarus-afd/)
- [2]Microsoft Security Response Center: CVE-2026-68820 Advisory(https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820)