HomeRisk ManagementsLazarus Employs Post-Quantum Key Exchange to Launch Zero-Day Attack

Lazarus Employs Post-Quantum Key Exchange to Launch Zero-Day Attack

Published on

spot_img

North Korea’s Lazarus Group Leverages Advanced Techniques in Cyber Attacks Against Defense and Aerospace Industries

In a troubling development in cybersecurity, Check Point Research has revealed that North Korea’s notorious Lazarus group has utilized sophisticated techniques to orchestrate cyberattacks aimed primarily at defense and aerospace companies in Europe and India. The malware employed during these attacks negotiated its command channel through a post-quantum key exchange mechanism, a move that signifies the increasing sophistication and evolving strategies employed by cybercriminals.

Key Findings and Vulnerability Reports

On July 28, Check Point Research flagged a significant vulnerability, designated as CVE-2026-68820, which was later reported to Microsoft. The analysis of this vulnerability was published on August 11, coinciding with the release of Microsoft’s patch to mitigate the threat. The flaw was identified as a use-after-free race condition within AFD.sys, a driver responsible for managing network sockets in the Windows kernel. Alarmingly, it was the only vulnerability among the numerous flaws addressed during the August Patch Tuesday that Microsoft highlighted as being actively exploited by malicious actors.

This incident forms part of an extensive campaign known as Operation Dream Job, during which the Lazarus group aims to infiltrate defense firms by luring employees with fraudulent job offers. Initial reports indicate that the group’s activities have primarily targeted organizations involved in cutting-edge technologies such as surveillance sensors, drones, and robotics, indicating a focus on critical sectors tied to national security. Nations such as France, Germany, Brazil, and India have reported instances of this nefarious campaign.

Infection Mechanism and Command Channel

The malware infection path began with MISTPEN, an in-memory downloader that communicated with the attackers through files hosted on OneDrive, utilizing the Microsoft Graph API for transmission. Following reconnaissance and persistence phases, the malware loaded a specific module designed to acquire the privilege escalation exploit crucial for further infiltration.

This particular module performed a host fingerprinting task to identify vulnerabilities and subsequently requested four public keys from the command server. Utilizing the Kyber/ML-KEM key encapsulation scheme, which is an emerging standard aimed at resisting quantum computer attacks, the module generated fresh key material and transmitted it back to the attacker, before decrypting and executing the exploit in memory. The careful layering of encryption—worth noting was GOST-CBC layered on top of MISTPEN’s AES transport encryption—indicates the advanced level of security employed by the attackers to mask their activities.

The FudModule: An Evasive Kernel Rootkit

What was delivered through this two-layer handshake was FudModule, a kernel rootkit that Check Point has tracked as version 3.1. This sophisticated piece of malware works by disabling telemetry callbacks, removing minifilters, and neutralizing the NT Kernel Logger, thereby obfuscating the attackers’ activities. Notably, it also blinds 94 Event Tracing for Windows (ETW) providers, significantly hampering detection efforts. Among its newly added functionalities is the ability to tamper with Smart App Control, resetting its policy state, and forcing a reload of code integrity. This level of sophisticated evasion reinforces the persistent threat posed by the Lazarus group.

Infrastructure and Delivery Mechanisms

The infrastructure behind this sophisticated operation was predominantly hosted on servers that the Lazarus group did not own outright. They exploited Roundcube webmail servers using the CVE-2025-49113 vulnerability and likely employed credentials obtained from dark web leaks in combination with compromised PrestaShop sites. Each of these servers hosted RelayShell, a PHP webshell that functions as a message relay, channeling traffic between the operators and their victims via session files.

Delivery tactics have also evolved, with the group setting up at least three websites that masquerade as those of privacy technology vendor Enveil, ranking high in search engine results. It is crucial to note that Enveil was neither targeted nor compromised; however, the fraudulent sites distributed a trojanized PDF viewer embedding a payload within crafted documents. This payload, known as Troy, supports 17 operator commands, further demonstrating the group’s commitment to advancing their operational capabilities.

Conclusion

The advancements in cyber espionage techniques, particularly by groups like Lazarus, underscore the critical need for organizations in defense and aerospace sectors to bolster their cybersecurity measures. The targeted attacks, utilizing complex malware strategies and deception techniques, highlight the severe implications for national security. As cyber threats continue to evolve, ongoing vigilance and swift adaptation to emerging threats will be essential for safeguarding sensitive information and maintaining operational integrity in these crucial fields.

Source link

Latest articles

Edtech Faces Challenges from Third-Party Cyber Threats

Edtech Faces Rising Cyber Threats Amid Historic Attacks The landscape of education technology has become...

Vega Unveils Detection Skills: The New Open Standard for AI Reasoning in Agentic Cyber Defense

Vega Unveils Detection Skills: A Groundbreaking Open Standard for AI-Powered Cyber Defense In a significant...

Axonius CEO Cautions That AI Exacerbates Asset Visibility Gaps

Diamond: AI Agents Can Interact With Cloud Apps and Endpoints Across the Enterprise By Michael...

More like this

Edtech Faces Challenges from Third-Party Cyber Threats

Edtech Faces Rising Cyber Threats Amid Historic Attacks The landscape of education technology has become...

Vega Unveils Detection Skills: The New Open Standard for AI Reasoning in Agentic Cyber Defense

Vega Unveils Detection Skills: A Groundbreaking Open Standard for AI-Powered Cyber Defense In a significant...