ALITEQ.

North Korean hackers had a Windows bug for weeks before Microsoft even knew about it

Check Point caught the exploit chain in the wild before Microsoft's own August Patch Tuesday shipped the fix — and this one installs a kernel-mode rootkit.

Priya NairUpdated 50m ago6 min readWeb story
A laptop running Windows in a dim office setting, at night

Microsoft's August Patch Tuesday fixed 421 CVEs on August 11 — a number large enough that most of them blur together. One didn't: CVE-2026-68820, a privilege-escalation bug in the Windows kernel driver that handles socket operations, which Check Point had already caught North Korean hackers using in real intrusions before the patch existed. Check Point traces the exploitation back to at least early July — meaning attackers had roughly a month's head start.

What AFD.sys actually is, and why a bug there matters

AFD.sys, the Ancillary Function Driver for WinSock, is the kernel-mode component that every piece of networking software on Windows ultimately routes through when it opens a socket. It's not an obscure corner of the OS; it's plumbing that Chrome, Slack, a VPN client and Windows Update itself all touch, which is exactly why a bug in it is valuable to an attacker who already has a toehold. CVE-2026-68820 is a use-after-free: a race condition lets a specially crafted local application trigger a memory-handling error that hands the attacker kernel-level memory access, and from there, SYSTEM privileges.

How this one played out

  1. Early Jul 2026

    Check Point observes North Korean threat actors exploiting an unknown Windows flaw to deploy a kernel-mode rootkit in a new Operation Dream Job wave.

  2. Jul 28, 2026

    Check Point reports the vulnerability to the Microsoft Security Response Center.

  3. Jul 31, 2026

    Microsoft confirms the issue.

  4. Aug 5, 2026

    CVE-2026-68820 is formally assigned.

  5. Aug 11, 2026

    Fix ships as part of Patch Tuesday, alongside 420 other CVEs.

Operation Dream Job: still fake job offers, still working

Operation Dream Job is the campaign name security researchers use for a long-running North Korean tactic: pose as a recruiter, usually for a defense contractor or crypto firm, and get a target to open a 'coding test' or job-offer document that's actually a loader. It's not a new idea — this campaign has been documented since at least 2020 — and the fact that it's still landing kernel-level rootkits in 2026 says less about the lure's cleverness and more about how hard privilege-escalation bugs are to fully stamp out. Getting code running on a target's machine has always been step one. AFD.sys just gave step two a shortcut to SYSTEM.

A laptop running Windows in a dim office setting at night
AFD.sys sits deep in the Windows networking stack — nearly every application with a socket connection routes through it. · Unsplash

How this compares to the other 'exploited' Microsoft bug this month

Two 'exploited' August bugs, two different stories

CVE-2026-68820 (AFD.sys)

Confirmed exploited

vs

CVE-2026-69836 (Entra ID)

Exploitation claim retracted

7.0
CVSS score
10.0
Confirmed — Check Point traced it to Operation Dream Job
Exploitation status
Initially tagged exploited, then Microsoft corrected it to 'No' after investigation
Local — attacker needs code execution first
Attack vector
Remote, unauthenticated in theory — patched server-side
Deploy the August 11 update across every Windows endpoint
What it actually needs from you
Nothing — Microsoft's fix applied automatically to the cloud service
(AFD.sys) wins 0wins 0 ID)

We wrote about the Entra ID saga when Microsoft first tagged, then corrected, CVE-2026-69836's exploitation status — the higher CVSS score there made bigger headlines, but AFD.sys is the one with an actual documented victim chain behind it. Worth remembering next time a 10.0 score and a 7.0 score compete for your attention: the number alone doesn't tell you which one attackers are using today.

Confirm the August 11, 2026 cumulative update is deployed across all Windows endpoints, not just servers.

2

Prioritize machines with elevated network exposure or admin-adjacent user accounts — the highest-value targets for a local-to-SYSTEM chain.

3

Review EDR and rootkit-detection coverage; Check Point's writeup notes the deployed rootkit specifically targets kernel-level persistence, which userland-only tooling can miss.

4

If your org fits Operation Dream Job's usual targets — defense, crypto, gaming, or media — treat unsolicited 'coding assessment' attachments as hostile by default.

CVE-2026-68820: quick answers

Do I need to do anything if I already installed August's Patch Tuesday updates?
No — the August 11 cumulative update contains the fix. If you're current on Windows Update, you're patched.
Can this be exploited remotely?
No. It requires local code execution first — an attacker or malware already running on the machine uses it to escalate from a limited account to SYSTEM.
Is this related to the Entra ID CVSS 10.0 bug from the same week?
No — different product, different vendor team, unrelated exploit chain. They just landed in headlines around the same time.
Who's actually being targeted?
Check Point's reporting ties exploitation to Operation Dream Job, North Korea's long-running fake-recruiter campaign, historically aimed at defense, cryptocurrency, and tech-sector employees.

421 CVEs in one Patch Tuesday is the kind of number that makes people's eyes glaze over and skip straight to 'I'll get to it.' This is the one bug in that pile with a documented nation-state actor already using it a month before the fix existed — if you triage patches by severity score alone, move this one up regardless of what else is queued. We'll keep tracking how this month's other high-profile Windows bugs — including the WDS TFTP RCE fix that broke PXE boot, the Defender zero-day CISA gave a 14-day window on, and its subsequent patch bypass — play out against Microsoft's patch cadence.

Software & Systems Editor

Priya Nair

Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading