Rewterz

Gunra Ransomware Exploits Fortinet VPN Flaws – Active IOCs

August 11, 2026
Rewterz

Ivanti EPM Flaws Enable Remote Service Crashes

August 12, 2026

Windows AFD.sys Zero-Day Exploited by Lazarus – Active IOCs

Severity

High

Analysis Summary

North Korea-linked Lazarus has been observed exploiting a newly disclosed Windows kernel zero-day, CVE-2026-68820, to deploy an upgraded version of its FudModule rootkit. The vulnerability affects AFD.sys (Ancillary Function Driver), which operates within the Windows kernel to manage network sockets, and was patched by Microsoft on August 11, 2026, following responsible disclosure by Research. The activity is part of a new phase of the Operation Dream Job espionage campaign targeting defense, aerospace, and aviation organizations. Lazarus continues to use fake recruitment offers as the initial social-engineering lure, convincing victims to download malicious files disguised as legitimate job-related documents.

Researcher identified two infection chains. The first uses DLL sideloading through an encrypted ZIP archive containing a legitimate signed PDF viewer, a malicious libmupdf.dll, and an encrypted payload disguised as a PDF. The second uses a trojanized PDF viewer named SecurityPDF, based on the open-source MuPDF framework and designed to impersonate Enveil. Lazarus also created SEO-optimized websites to promote the malicious viewer in search results. Both chains ultimately deliver MISTPEN, an in-memory downloader that uses the Microsoft Graph API to retrieve additional modules from attacker-controlled OneDrive storage over AES-encrypted communications. MISTPEN initially performs reconnaissance and captures screenshots to determine whether the victim is a worthwhile target before delivering the privilege-escalation component that exploits CVE-2026-68820.

Successful exploitation provides SYSTEM-level privileges and enables deployment of FudModule v3.1, the latest version of Lazarus's kernel-mode rootkit. The rootkit maintains its ability to disable security and monitoring mechanisms by removing telemetry callbacks, disabling minifilters, terminating the NT Kernel Logger, and suppressing more than 90 ETW providers. Unlike earlier versions, FudModule v3.1 removes its dedicated Microsoft Defender-disabling routine and instead uses a more generic security-product suppression mechanism. It also introduces the ability to tamper with Smart App Control by resetting its verified-and-reputable policy state. After gaining elevated privileges, the malware injects MISTPEN into a SYSTEM process to evade many EDR detections before deploying additional payloads, including the established ForestTiger backdoor or Troy, a newly identified 17-command modular implant supporting file theft, remote command execution, and in-memory DLL injection.

Lazarus further attempted to conceal its command-and-control infrastructure by routing traffic through compromised Roundcube webmail and WordPress or PrestaShop servers instead of dedicated attacker-controlled infrastructure. Some Roundcube systems had reportedly been compromised through CVE-2025-49113 using credentials obtained from the dark web. The attackers installed RelayShell, a PHP web shell that forwards commands through file-based messaging rather than directly executing them on compromised servers, helping the traffic appear like normal web activity. Researcer identified at least 17 compromised relay nodes and observed the attackers using VPN services such as ExpressVPN to obscure their origins. Organizations running Windows 11 builds 26100 or 26200 should prioritize Microsoft's August 2026 security updates to address CVE-2026-68820, while security teams particularly in defense and aerospace should monitor for suspicious recruitment-themed files, malicious PDF viewers, MISTPEN activity, abnormal Microsoft Graph/OneDrive access, kernel-level security tampering, and outbound connections to compromised Roundcube, WordPress, or PrestaShop infrastructure.

Impact

  • Gain Access

Indicators of Compromise

CVE

  • CVE-2026-68820

  • CVE-2024-38193

  • CVE-2025-49113

Domain News

  • envell.xyz

  • enveil.online

  • uxtramine.org

IP

  • 135.181.67.203

  • 135.181.185.158

MD5

  • 329dcba41a6a070dae647c9d72ec5fec
  • ecbe5171265aef1f88d3b12a7891a949
  • 8a1ff3e23a209bfe920e01a61a6769aa
  • 56d15f308984c1a388c112ac39dfb18a
  • 07c9e9716abfdb91cb11ac1dfd0ea536
  • 718706333b6f2251f13f62885ba0156d
  • 07bfd8b5cf77a22d6029c3fcf9157ecd

SHA-256

  • 2b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca8
  • 13d10bc99f7f7abe7ee0902be87920b73b2ea41bd9683dbfcad340dacbcdef79
  • a673ae661593c0de9bbb815593b816a6853dad6d55ad5042d2ef1875cd13d6e7
  • d578c28c9afe7457a0d81f6701332ef8197e8f7468de654935fb29a50ea66459
  • acb97cec84e08b89f41967a24e965d1fd2c51751cef158f7aa35bb4306b87b97
  • db3d69b7eeda2e35e23006bf4b7e206281fce809584207214fc213f9bc30376d
  • a738059ce07c951c31ab2da3d93d8f69bff32f9b7d933dbf5943441b9cc99075

SHA1

  • 9eec3bd5ea0686f22d6d68b2d99151211b89d912
  • 8a269ae11275421e6302ab3714fc61e1b7960576
  • b68c0cf7d1e563dad02fb2fad3590e43399c140b
  • 684538f963443a15872c79771197135224aea34e
  • 1857213d27b7ae42147f820218b92a4158837335
  • e69d84517c8f95173a0a8a3d0f5dcf0fbe051a0e
  • 60226f03e6ac978eb4ddbb55fa2f23f68aaabe53

Remediation

  • Install Microsoft's August 2026 security updates to address CVE-2026-68820, especially on Windows 11 builds 26100 and 26200.
  • Prioritize patching systems used by defense, aerospace, aviation, and other sensitive organizations.
  • Train employees to identify fake recruitment offers, suspicious job descriptions, unexpected ZIP files, and malicious PDF viewers.
  • Monitor and restrict unauthorized DLL sideloading, particularly DLL execution from temporary or user-writable directories.
  • Monitor for attempts to disable ETW providers, kernel logging, minifilters, telemetry callbacks, Microsoft Defender, and Smart App Control.
  • Hunt for MISTPEN activity, including unusual Microsoft Graph API and OneDrive connections combined with in-memory execution.
  • Monitor for abnormal SYSTEM-level process injection, privilege escalation, and DLL injection.
  • Monitor outbound connections to suspicious or compromised Roundcube, WordPress, and PrestaShop infrastructure.
  • Ensure internet-facing Roundcube, WordPress, PrestaShop, and other applications are fully patched, including protection against CVE-2025-49113.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.