HomeCyber BalkansLazarus Group Exploits Windows Zero-Day in Operation Dream Job

Lazarus Group Exploits Windows Zero-Day in Operation Dream Job

Published on

spot_img

North Korean Lazarus Group Exploits Windows Vulnerability in New Cyber Campaign

A new wave of cyberattacks has emerged, orchestrated by the North Korean state-sponsored threat actor known as the Lazarus Group. Security researchers from Check Point have disclosed the group’s exploitation of a zero-day vulnerability in Windows as part of their ongoing Operation Dream Job campaign. The campaign primarily aims at defense and aerospace sectors in Europe and India, using deceptive job offers distributed through platforms like LinkedIn and direct messaging systems.

The vulnerability exploited in these attacks is identified as CVE-2026-68820, a use-after-free privilege escalation flaw in the Windows Ancillary Function Driver for WinSock. This critical flaw was patched by Microsoft during its August 2026 Patch Tuesday release. The nature of this vulnerability allows the Lazarus Group to gain elevated privileges, thus facilitating the deployment of sophisticated malware.

The modus operandi of the attack begins with the perpetrators posing as recruiters from credible companies. Victims are instructed to download PDF files purportedly containing job details. According to Check Point, two primary attack chains were identified. In the first variant, victims receive a compressed archive that includes a malicious DLL file, an encrypted payload camouflaged as a PDF, and a legitimate digitally signed PDF viewer, SmartaPDF.exe.

Upon running the viewer, the malicious DLL is sideloaded, which then decrypts and executes a downloader known as MISTPEN. This process is cleverly concealed through the display of a decoy job description, thereby avoiding suspicion from the target.

Once activated, MISTPEN establishes communication with the attacker’s infrastructure via the Microsoft Graph API and OneDrive. It performs reconnaissance and persistence functions before employing the CVE-2026-68820 vulnerability to achieve kernel-level access. This escalation of privileges enables the installation of FudModule v3.1, a rootkit designed to disable logging systems, suppress security measures, and, in its recent iterations, disrupt Windows Smart App Control. This complex chain ultimately leads to the deployment of the ForestTiger backdoor.

The second attack variant is even more insidious. It employs a trojanized PDF viewer, dubbed SecurityPDF, hosted on a domain masquerading as a privacy technology company, Enveil. This approach introduces a novel backdoor named Troy, which supports 17 different commands, including shell access, process termination, and file exfiltration.

Denis Calderone, Chief Technology Officer at Suzu Labs, highlighted that this incident marks at least the third occasion in a span of two years where the Lazarus Group has leveraged vulnerabilities in built-in Windows drivers—previous examples include CVE-2024-21338 and CVE-2024-38193. The group’s tactics have evolved from a traditional "bring-your-own-vulnerable-driver" approach to exploiting drivers that are equipped by default on Windows systems. For instance, AFD.sys manages socket operations on all Windows machines and is immune to blocklist strategies.

Moreover, Check Point researchers observed that the Lazarus Group is increasingly utilizing compromised WordPress and Roundcube Webmail servers as part of their command-and-control infrastructure. Many of these Roundcube instances are vulnerable due to CVE-2025-49113, a remote code execution flaw, further complicating defenses against these attacks.

In response to this alarming situation, the Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog. The agency has mandated that all federal civilian executive branch agencies must apply the necessary patches by August 25. Notably, while the vulnerability carries a CVSS score of 7.0 and has been classified as "Important" rather than "Critical," security experts caution that organizations that prioritize vulnerabilities solely based on severity scores may overlook this actively exploited flaw in favor of theoretical remote code execution exploits.

Experts strongly advise organizations within the defense, aerospace, and related industries to prioritize the deployment of patches, scrutinize LinkedIn and recruitment-related communications for any signs of suspicious activity, and stay vigilant for indicators of compromise linked to malicious payloads such as MISTPEN, ForestTiger, Troy, and FudModule. Constant vigilance and immediate remediation efforts are necessary to mitigate the risks posed by these sophisticated cyber threats.

By following this guidance, organizations can better prepare themselves against the evolving cyber landscape and the persistent threats posed by state-sponsored actors.

Source link

Latest articles

CISA Issues Alert on Critical Vulnerability in Johnson Controls Metasys Systems

Critical Flaw Disclosed in Building Automation System A significant security vulnerability in Johnson Controls’ Metasys...

Microsoft Copilot App Revamp Combines Personal Chats and Discontinues Podcasts and Deep Research

Microsoft is undergoing a significant transformation in its consumer and productivity AI strategy with...

Is AI Integrating into the SOC at the Appropriate Stage?

The Challenge of Alert Fatigue in Security Operations Centres In the rapidly evolving digital landscape,...

Chess.com Data Breach Exposes 7.3 Million Users Through Scraping

Data Breach of Chess.com: 7.3 Million User Profiles Compromised In a staggering revelation, over 7.3...

More like this

CISA Issues Alert on Critical Vulnerability in Johnson Controls Metasys Systems

Critical Flaw Disclosed in Building Automation System A significant security vulnerability in Johnson Controls’ Metasys...

Microsoft Copilot App Revamp Combines Personal Chats and Discontinues Podcasts and Deep Research

Microsoft is undergoing a significant transformation in its consumer and productivity AI strategy with...

Is AI Integrating into the SOC at the Appropriate Stage?

The Challenge of Alert Fatigue in Security Operations Centres In the rapidly evolving digital landscape,...