The recruiter answered every email: how Lazarus planted a kernel rootkit inside European defence firms
Lazarus paired fake job offers and DLL side-loading in a PDF viewer with zero-day CVE-2026-68820 in afd.sys to plant the FudModule rootkit inside European defence firms.
By Thilina Manana · COO, Director Técnico de Seguridad hard2bit y socio fundador