North Korean hackers linked to the Lazarus threat group have been exploiting a Windows zero-day vulnerability to target defense-sector organizations as part of the long-running Operation Dream Job campaign.

The vulnerability, tracked as CVE-2026-68820, was addressed by Microsoft in its August 2026 Patch Tuesday security updates after the company confirmed that it was being actively exploited. The flaw is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, known as AFD.sys, and can be used to elevate local privileges.

Microsoft says a locally authenticated attacker can run a specially crafted application on a vulnerable system to trigger a race condition and eventually obtain SYSTEM privileges without requiring user interaction. The flaw has a CVSS score of 7.0 and is particularly useful after an attacker has already gained an initial foothold on a machine.

The latest activity is part of Operation Dream Job, a campaign in which Lazarus actors use fake recruitment offers to target employees at organizations of interest. Recent attacks have focused on defense, aerospace and aviation organizations in Europe and India, with targets involved in areas such as military technology, surveillance sensors, drones and robotics.

According to the supplied research, Check Point researchers found that Lazarus incorporated an exploit for CVE-2026-68820 into a new version of its FudModule kernel-mode rootkit. The exploit was designed to work against Windows 11 builds 26100 and 26200 and was used to elevate privileges after the attackers gained access to targeted systems.

READ
737 Fake VPN Chrome Extensions Found Routing User Traffic Through Proxies

This is not the first time Lazarus has abused a zero-day vulnerability in the AFD.sys driver to gain higher privileges and deploy FudModule. The latest version of the rootkit retains capabilities previously associated with the malware, including disabling EDR telemetry and interfering with security products, while also adding the ability to tamper with Windows Smart App Control.

The attackers have also introduced a new backdoor called Troy. According to the research, the malware supports 17 commands that allow the attackers to perform system and process reconnaissance, upload and download files, delete files, archive data for exfiltration, execute commands in hidden ways, terminate remote processes, inject DLLs directly into memory and modify configuration and beacon timing.

The campaign also involved compromised Roundcube email servers. Researchers observed scans for vulnerable Roundcube installations that were later compromised with a new PHP web shell called RelayShell.

The attackers appear to have used leaked credentials to authenticate to Roundcube before exploiting CVE-2025-49113, an authenticated PHP object-deserialization vulnerability, to achieve remote code execution. At least 17 servers were identified as infected with RelayShell based on the identifiers recovered by researchers.

The latest Operation Dream Job activity has reached organizations in multiple regions, including Western Europe and South America. Researchers observed successful targeting in countries including France, Germany and Brazil, while a compromised organization in France was also used to launch spear-phishing attacks against additional targets.

The campaign also shows how the attackers are using legitimate but compromised infrastructure to make their operations harder to detect. By abusing compromised Roundcube servers for malicious communications, Lazarus can hide parts of its activity behind infrastructure that would normally be considered legitimate.


Buy ExpressVPN with PayPal or Credit Card
READ
Webmail Security Flaws Let Email Content Break Out of the Inbox and Steal Sensitive Data

Microsoft has now released security updates addressing CVE-2026-68820, while Check Point has published indicators of compromise associated with the attacks along with a YARA rule designed to help organizations detect the RelayShell web shell.

Advertisement