The North Korean state-sponsored threat actor Lazarus Group has launched a new wave of its Operation Dream Job campaign, exploiting a Windows zero-day vulnerability to deploy sophisticated malware. Check Point researchers reported Tuesday that the attacks leverage CVE-2026-68820, a use-after-free privilege escalation flaw in the Windows Ancillary Function Driver for WinSock, which Microsoft patched in its August 2026 Patch Tuesday release. The campaign primarily targets defense and aerospace organizations in Europe and India through fraudulent job offers sent via LinkedIn and other direct messaging platforms.
The attack begins with threat actors posing as recruiters from well-known companies, instructing victims to download PDF files containing supposed job details. Check Point identified two distinct attack chains. In the first variant, victims receive an archive containing a malicious DLL, an encrypted payload disguised as a PDF, and a legitimate digitally signed PDF viewer called SmartaPDF.exe. When launched, the viewer sideloads the malicious DLL, which decrypts and executes a downloader called MISTPEN while displaying a decoy job description to avoid suspicion.
MISTPEN communicates with attacker infrastructure through Microsoft Graph API and OneDrive, running reconnaissance and persistence modules before exploiting CVE-2026-68820 to gain kernel-level access. This privilege escalation enables deployment of FudModule v3.1, a rootkit that disables logging systems, suppresses security software, and in its latest version, disrupts Windows Smart App Control. The attack chain ultimately deploys the ForestTiger backdoor. A second attack variant uses a trojanized PDF viewer called SecurityPDF, hosted on a domain impersonating privacy technology company Enveil, which deploys a novel backdoor named Troy that supports 17 commands including shell access, process termination, and file exfiltration.
Denis Calderone, CTO at Suzu Labs, noted this marks at least the third time in two years that Lazarus has exploited vulnerabilities in built-in Windows drivers to deploy FudModule, having previously leveraged CVE-2024-21338 and CVE-2024-38193. The group has adapted its tactics from the traditional bring-your-own-vulnerable-driver approach to targeting drivers that Windows ships by default, such as AFD.sys, which handles socket operations on every Windows machine and cannot be blocklisted. Check Point researchers also observed Lazarus increasingly using compromised WordPress and Roundcube Webmail servers as command-and-control infrastructure, with many Roundcube instances vulnerable to CVE-2025-49113, a remote code execution flaw.
CISA has added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog, ordering federal civilian executive branch agencies to patch by August 25. Despite carrying a CVSS score of 7.0 and being rated Important rather than Critical, security experts warn that organizations triaging by severity score alone may deprioritize this actively exploited vulnerability behind theoretical remote code execution bugs. Organizations in defense, aerospace, and related sectors should prioritize patching, review LinkedIn and recruitment-related communications for suspicious activity, and monitor for indicators of compromise associated with MISTPEN, ForestTiger, Troy, and FudModule.
Source: https://www.scworld.com/news/dprks-lazarus-group-exploits-windows-zero-day-in-backdoor-campaign


