INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
North Korean Lazarus Group Exploits Windows Zero-Day
| 2026-08-13 07:05 CRITICAL HIGHExecutive Summary AI-generated
The North Korean Lazarus Group has launched a new wave of Operation Dream Job, exploiting a previously unknown Windows vulnerability to gain full control of infected computers and evade EDR visibility. The group's tactics include hijacking legitimate websites and webmail servers, deploying backdoors such as ForestTiger and FudModule 3.1, and using compromised Roundcube infrastructure to establish command and control (C2) connections with its operatives. This iteration is more dangerous than previous versions due to the newly documented Troy backdoor and the use of hijacked legitimate servers, making it harder for endpoint security solutions to detect and block the malicious traffic.
Technical Mitigations AI-generated
* Use up-to-date and patched operating systems, software, and firmware to minimize the risk of exploitation.
* Implement robust security controls, such as firewalls, intrusion detection systems, and antivirus software, to detect and block malicious traffic.
* Conduct regular vulnerability assessments and penetration testing to identify potential weaknesses and address them before they can be exploited.
* Use secure coding practices, such as input validation and sanitization, to prevent the introduction of vulnerabilities in code.
* Implement a least-privilege access model for all users and systems, with strict controls on user privileges and permissions.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Dream JobOperation Dream JobOperation DreamJobOperation DreamJob
Lazarus GroupLazarus Group
CVE-2025-60719CVE-2025-60719
CVE-2026-59124CVE-2026-59124
CVE-2026-62878CVE-2026-62878
CVE-2026-62832CVE-2026-62832
CVE-2026-62893CVE-2026-62893
CVE-2026-68820CVE-2026-68820
CVE-2026-72971CVE-2026-72971
CVE-2025-49113CVE-2025-49113
CVE-2026-55040CVE-2026-55040
CVE-2026-63520CVE-2026-63520
CVE-2026-62911CVE-2026-62911
CVE-2026-62815CVE-2026-62815
CVE-2024-38193CVE-2024-38193
Target & Sectors
DPRK
DPRK
FIVE_EYES
FIVE_EYES
LATAM
LATAM
DACH
DACH
aerospaceaerospace
technologytechnology
governmentgovernment
aviationaviation
defensedefense
mediamedia
Incident Timeline
around 2021
Threat actors used the Lazarus Group's FudModule to exploit a Windows Zero-Day vulnerability and gain system access.
Click on any entity below to view its context and source!
tactic
Privilege Escalation
FudModule is a Lazarus privilege escalation tool, reported and being used since around 2021.
2025/08/11
Threat actors used Lazarus Group's Windows Zero-Day exploit to gain system access through a backdoor installed by the Troy malware.
Click on any entity below to view its context and source!
organisation
ESET
For example, an ESET
report
published last year documented a sample containing a PDB path
E:\Work\Troy\안정화\...
The Troy backdoor supports three Command and Control (C2) servers, each configured with a URL and port.
organisation
E:\Work\Troy\안정화\
For example, an ESET
report
published last year documented a sample containing a PDB path
E:\Work\Troy\안정화\...
The Troy backdoor supports three Command and Control (C2) servers, each configured with a URL and port.
organisation
Command and Control
For example, an ESET
report
published last year documented a sample containing a PDB path
E:\Work\Troy\안정화\...
The Troy backdoor supports three Command and Control (C2) servers, each configured with a URL and port.
2025/08/12
Threat actors exploited a recently discovered Windows Zero-Day vulnerability to gain system access.
November 2025
Threat actors exploited a previously unknown Windows Zero-Day vulnerability, CVE-2025-60719.
Click on any entity below to view its context and source!
vulnerability
CVE-2025-60719
At first sight, the vulnerability looked similar to
CVE-2025-60719
, which is also a use-after-free vulnerability in the AFD.sys driver fixed in November 2025 and not linked to any particular threat actor.
May 18
The Lazarus Group exploited a Windows Zero-Day vulnerability to gain system access through an authentication bypass and code execution on May 18.
July 7, 2026
Threat actors exploited a recently discovered Windows Zero-Day (CVE-2026-68820) in the Afd4Eop12_x64.dll file.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-68820
CVE-2026-68820: Yet another Zero-Day discovered by Lazarus
The file we investigated,
Afd4Eop12_x64.dll
, has a compiler timestamp of
July 7, 2026, 22:07:44 UTC
.
observable
Afd4Eop12_x64.dll
CVE-2026-68820: Yet another Zero-Day discovered by Lazarus
The file we investigated,
Afd4Eop12_x64.dll
, has a compiler timestamp of
July 7, 2026, 22:07:44 UTC
.
organisation
UTC
CVE-2026-68820: Yet another Zero-Day discovered by Lazarus
The file we investigated,
Afd4Eop12_x64.dll
, has a compiler timestamp of
July 7, 2026, 22:07:44 UTC
.
2026/07/13
Threat actors used a newly discovered Windows Zero-Day exploit to gain system access.
Click on any entity below to view its context and source!
organisation
LegacyHive
The details of the vulnerability appear to match a proof-of-concept called LegacyHive published by the pseudonymous researcher Nightmare Eclipse hours after last month’s Patch Tuesday — the latest instalment in a
months-long standoff
over the company’s disclosure and bounty practices.
organisation
Nightmare
The details of the vulnerability appear to match a proof-of-concept called LegacyHive published by the pseudonymous researcher Nightmare Eclipse hours after last month’s Patch Tuesday — the latest instalment in a
months-long standoff
over the company’s disclosure and bounty practices.
July 2026
Threat actors used a newly discovered Windows Zero-Day to infect systems through a Trojanized PDF viewer.
Click on any entity below to view its context and source!
campaign
Operation Dream Job
Infection Chain 2: Trojanized PDF viewer
In July 2026
,
we observed a new campaign sharing many characteristics with previously documented
Operation Dream Job
, particularly the campaign
described
by
ESET
in 2025.
general_metric
2.0 reference
Infection Chain 2: Trojanized PDF viewer
In July 2026
,
we observed a new campaign sharing many characteristics with previously documented
Operation Dream Job
, particularly the campaign
described
by
ESET
in 2025.
at least early July 2026
Threat actors used a previously undisclosed Windows Zero-Day vulnerability to target an unpatched version of the operating system.
Click on any entity below to view its context and source!
infrastructure
Windows
However, testing on the latest fully patched Windows 11 system confirmed that the exploit targets a distinct, previously undocumented vulnerability, actively being used in the wild as a part of Operation ‘Dream Job’ since at least early July 2026.
general_metric
11 Windows
However, testing on the latest fully patched Windows 11 system confirmed that the exploit targets a distinct, previously undocumented vulnerability, actively being used in the wild as a part of Operation ‘Dream Job’ since at least early July 2026.
organisation
Operation ‘Dream Job
However, testing on the latest fully patched Windows 11 system confirmed that the exploit targets a distinct, previously undocumented vulnerability, actively being used in the wild as a part of Operation ‘Dream Job’ since at least early July 2026.
July 28
Check Point Research discovered and reported the vulnerability to Microsoft on July 28, which was then confirmed by Microsoft three days later.
Click on any entity below to view its context and source!
organisation
Check Point Research
Check Point Research reported the vulnerability to Microsoft on July 28 and
published its analysis
on August 11, the day a patch shipped.
organisation
Microsoft
Check Point Research reported the vulnerability to Microsoft on July 28 and
published its analysis
on August 11, the day a patch shipped.
Jul 28, 2026
Threat actors exploited a recently discovered Windows zero-day vulnerability to gain system access.
Jul 31, 2026
Threat actors exploited a previously unknown Windows Zero-Day vulnerability to gain unauthorized access to targeted systems.
Aug 5, 2026
Threat actors exploited a recently discovered Windows Zero-Day vulnerability to gain system access.
August 11
Threat actors used a previously unknown Windows Zero-Day vulnerability, CVE-2026-68820, to gain system access by hijacking legitimate websites and webmail servers.
Click on any entity below to view its context and source!
infrastructure
Windows
“Rather than running their own servers, the attackers are hijacking legitimate but compromised websites and webmail servers to relay commands, making the malicious traffic harder to distinguish from normal activity”
The vulnerability, CVE-2026-68820, is the same actively exploited zero-day that Microsoft patched on August 11 as part of
Patch Tuesday
, a privilege escalation flaw in AFD.sys, the kernel driver underlying Windows Sockets.
tactic
Privilege Escalation
“Rather than running their own servers, the attackers are hijacking legitimate but compromised websites and webmail servers to relay commands, making the malicious traffic harder to distinguish from normal activity”
The vulnerability, CVE-2026-68820, is the same actively exploited zero-day that Microsoft patched on August 11 as part of
Patch Tuesday
, a privilege escalation flaw in AFD.sys, the kernel driver underlying Windows Sockets.
vulnerability
CVE-2026-68820
“Rather than running their own servers, the attackers are hijacking legitimate but compromised websites and webmail servers to relay commands, making the malicious traffic harder to distinguish from normal activity”
The vulnerability, CVE-2026-68820, is the same actively exploited zero-day that Microsoft patched on August 11 as part of
Patch Tuesday
, a privilege escalation flaw in AFD.sys, the kernel driver underlying Windows Sockets.
organisation
Check Point Research
Check Point Research reported the vulnerability to Microsoft on July 28 and
published its analysis
on August 11, the day a patch shipped.
organisation
Microsoft
Check Point Research reported the vulnerability to Microsoft on July 28 and
published its analysis
on August 11, the day a patch shipped.
Microsoft turned up the heat on sysadmins for the second month in a row on August 11 with a Patch Tuesday comprising 400 CVEs, including one actively exploited zero-day vulnerability.
August 11, 2026
Threat actors exploited a recently discovered Windows Zero-Day vulnerability, CVE-2026-68820.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-68820
Following responsible disclosure, Microsoft assigned the vulnerability
CVE-2026-68820
and released a patch on August 11, 2026, as part of their August Patch Tuesday updates.
Aug 11, 2026
Threat actors exploited a recently discovered Windows Zero-Day vulnerability to gain unauthorized access to targeted systems.
Aug 12, 2026
Threat actors exploited a recently discovered Windows zero-day vulnerability to gain unauthorized access to targeted systems.
August 2026
The Lazarus Group exploited CVE-2026-68820, a privilege escalation flaw in the Windows Ancillary Function Driver for WinSock.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-68820
The most urgent action is applying the August 2026 Patch Tuesday update, which contains the CVE-2026-68820 fix.
The
attacks
have been found to exploit
CVE-2026-68820
(CVSS score: 7.0), a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys") that was patched by Microsoft as part of its Patch Tuesday updates for August 2026.
infrastructure
Windows
The
attacks
have been found to exploit
CVE-2026-68820
(CVSS score: 7.0), a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys") that was patched by Microsoft as part of its Patch Tuesday updates for August 2026.
Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, GitHub Copilot, .NET, and a range of other components.
tactic
Privilege Escalation
The
attacks
have been found to exploit
CVE-2026-68820
(CVSS score: 7.0), a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys") that was patched by Microsoft as part of its Patch Tuesday updates for August 2026.
organisation
Microsoft
The
attacks
have been found to exploit
CVE-2026-68820
(CVSS score: 7.0), a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys") that was patched by Microsoft as part of its Patch Tuesday updates for August 2026.
Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, GitHub Copilot, .NET, and a range of other components.
organisation
Windows Ancillary Function
The
attacks
have been found to exploit
CVE-2026-68820
(CVSS score: 7.0), a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys") that was patched by Microsoft as part of its Patch Tuesday updates for August 2026.
infrastructure
7.0
The
attacks
have been found to exploit
CVE-2026-68820
(CVSS score: 7.0), a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys") that was patched by Microsoft as part of its Patch Tuesday updates for August 2026.
organisation
Patch Tuesday
The
attacks
have been found to exploit
CVE-2026-68820
(CVSS score: 7.0), a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys") that was patched by Microsoft as part of its Patch Tuesday updates for August 2026.
Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, GitHub Copilot, .NET, and a range of other components.
general_metric
7.0 attacks
The
attacks
have been found to exploit
CVE-2026-68820
(CVSS score: 7.0), a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys") that was patched by Microsoft as part of its Patch Tuesday updates for August 2026.
tactic
Remote Code Execution
Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE
Microsoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution.
organisation
DNS
Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE
Microsoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution.
organisation
SharePoint
Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, GitHub Copilot, .NET, and a range of other components.
organisation
Windows, Office
Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, GitHub Copilot, .NET, and a range of other components.
tactic
T1584.004 - Server
Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, GitHub Copilot, .NET, and a range of other components.
organisation
Teams
Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, GitHub Copilot, .NET, and a range of other components.
organisation
Microsoft Patch
Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE.
early 2026
Threat actors used a recently discovered Windows zero-day to gain system access.
Click on any entity below to view its context and source!
campaign
Operation Dream Job
Introduction
Since early 2026, Check Point Research has tracked a wave of the
Operation Dream Job
campaign.
2026/08/13
Lazarus Group exploited a newly patched Windows Zero-Day vulnerability to gain system access and deploy a backdoor.
Click on any entity below to view its context and source!
infrastructure
Windows
Vulnerability / Cyber Espionage
The North Korean threat actor known as
Lazarus Group
has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.
Malware used by North Korea's Lazarus group negotiated its command channel using a post-quantum key exchange before pulling down a Windows zero-day exploit, in a campaign against defense and aerospace companies across Europe and India.
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls.
Federal agencies were ordered to patch a Windows vulnerability used by North Korean hackers to target people applying to jobs in the defense and aerospace industry.
Lazarus hackers exploited Windows zero-day to target defense firms.
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign.
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job.
Researchers at cybersecurity company Check Point, tracking the latest variant of Operation Dream Job, found that Lazarus incorporated an exploit for CVE-2026-68820 that specifically supported Windows 11 builds 26100 and 26200 into a new version of the FudModule kernel-mode rootkit to elevate privileges.
MISTPEN then runs reconnaissance modules, triggers the AFD.sys exploit to achieve SYSTEM privileges, and deploys
ForestTiger
, a well-documented Lazarus backdoor, along with an updated version of the group’s kernel-mode rootkit,
FudModule
3.1, which can now tamper with Windows Smart App Control to bypass software verification.
This iteration is more dangerous than previous versions: it includes a previously unknown Windows vulnerability now patched as
CVE-2026-68820
, a newly documented backdoor called Troy, and command infrastructure built almost entirely from legitimate servers the attackers didn’t build, they hijacked them.
“The attackers used a previously unknown vulnerability in Windows (CVE-2026-68820) to gain full control of infected computers and evade EDR visibility.
It's the one confirmed-exploited bug in the release, and it applies to every Windows endpoint you manage.
Two were publicly disclosed before the patches dropped, while one of which —
CVE-2026-68820
, affecting the Windows component that handles network connections — has been seen exploited in the wild.
CVE-2026-68820 is a use-after-free race condition in AFD.sys, the driver handling network sockets in the Windows kernel, and was the only flaw in this the
August Patch Tuesday
release Microsoft flagged as under active exploitation.
What arrived through the handshake was FudModule, Lazarus's kernel rootkit, in a build Check Point tracks as v3.1.It disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger and blinds 94 Event Tracing for Windows (ETW) providers.
Microsoft says that the vulnerability is a "use-after-free in Windows Ancillary Function Driver for WinSock (AFD.sys)" that allows an attacker to increase their local privileges.
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor.
The newer version, called FudModule 3.1, improves upon its predecessor by allowing it to tamper with a Windows feature called
Smart App Control
designed to verify if a program is safe to run.
The actively exploited bug is
CVE-2026-68820
, a use-after-free flaw in afd.sys, the kernel-mode driver that underpins the Windows Sockets API.
CVE-2026-68820 is a Windows WinSock driver flaw that can let attackers execute code with SYSTEM-level privileges.
“Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.”
reads the advisory
.
CVE-2026-62878 is a critical Windows DNS Server flaw that allows remote, unauthenticated attackers to execute code with elevated privileges without user interaction.
CVE-2026-62893 hits Windows Deployment Services TFTP server, TFTP has no authentication, runs on UDP port 69, and any WDS server doing PXE boot is exposed.
Two publicly disclosed bugs — CVE-2026-62832 in Windows User Profile Service and CVE-2026-72971 in the Container Isolation FS Filter Driver — are also in this release, with the User Profile Service flaw considered likely to see exploitation.
The actively exploited zero day (CVE-2026-68820) is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock.
A locally authenticated attacker with low privileges could run a specially crafted application and trigger a race condition to gain system privileges and extensive control over a targeted Windows system.
CVE-2026-62832 is an Elevation of Privilege (EoP) vulnerability in the Windows User Profile Service which could allow an authenticated local attacker to elevate privileges.
The second publicly disclosed zero day which has yet to be exploited in the wild is CVE-2026-72971: a Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability.
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack.
Swati Khandelwal
Aug 11, 2026
Vulnerability / Windows Security
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.
The bug sits in a core Windows kernel driver that handles network socket operations.
They affect Windows DNS Server, Windows Deployment Services, Microsoft's implementation of the QUIC transport protocol, and High Performance Computing (HPC) Pack, and each carries a CVSS score of 9.8.
Check Point Research
said CVE-2026-68820 is a use-after-free in afd.sys, the
Ancillary Function Driver for WinSock
and a kernel-side component of Windows networking.
CVE-2026-62878, Windows DNS Server.
CVE-2026-62893, Windows Deployment Services.
Put CVE-2026-68820 at the top for Windows systems where an attacker already has code running and could use the flaw to reach SYSTEM.
During the operation, the threat actor deployed a new version of the
FudModule
rootkit, exploiting a zero-day local privilege escalation (LPE) vulnerability in the Windows
AFD.sys
driver, to obtain
SYSTEM
privileges and disable EDR visibility.
GetInfoPlugin – Host Reconnaissance Module
This module is a 64-bit Windows DLL internally named
Release_GetInfoPlugin_x64.dll
.
LPE loader
This module is a 64-bit Windows DLL that acts as a loader for a local privilege escalation (LPE) exploit module.
OsInfo: <Windows product name> <build_number>.<UBR>
PvPlugin – Process List Module
This module is a 64-bit Windows DLL internally named
Release_PvPlugin_x64.dll
.
OneScreenCapture – Screenshot Module
This module is a 64-bit Windows DLL internally named
OneScreenCapture64.dll,
it ****is responsible for capturing the current desktop (including all monitors) and returns the screenshot to its caller.
The module uses standard Windows
USER32
and
GDI
APIs to capture the virtual desktop into a bitmap.
The module targets
afd.sys
, the Windows Ancillary Function Driver, a part of the Windows kernel that is in charge of managing and handling sockets in Windows.
In the sample itself, we observed an explicit minimum-version check for
Windows 11
build 26100 (24H2)
, with explicit support also for
build 26200 (25H2)
.
Targeting
As mentioned before, this version only targets newer Windows builds 26100/26200, unlike the previous version that also targeted older ones.
Once authenticated, Troy collects host information and registers the victim by sending a client identifier and a system profile containing the user profile directory, account name, Windows version, local IPv4 address, and current working directory.
threat_actor
Lazarus Group
Vulnerability / Cyber Espionage
The North Korean threat actor known as
Lazarus Group
has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls.
The company tied the attacks to a campaign by Lazarus Group, which has been been targeting applicants for “attractive job opportunities at well-known companies in the defense, aerospace, and aviation industries” in a complicated attack that sees them combine PDFs with a trojanised reader allowing the hackers to secretly take control of the applicants’ machines.
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job.
Automox CTO Jason Kikta noted that the same component was previously exploited in 2024 by the Lazarus Group, an infamous hacking operation run out of North Korea’s Reconnaissance General Bureau.
A Check Point report
released
on Tuesday said Lazarus Group hackers impersonated recruiters for Lockheed Martin and privacy-tech firm Enveil, contacting people on LinkedIn and other sites before sending candidates malicious PDF files.
The use of a trojanized PDF viewer is a
tried-and-tested tactic
adopted by the
Lazarus Group
in conjunction with
Dream Job
, with the threat actors
abusing this method
as far back as 2022.
The attack chain employs an updated version of the known kernel-mode rootkit the Lazarus Group has
repeatedly
employed
since at least 2022
to conceal the presence of malicious tools from security software installed on the host.
The latest findings show that Lazarus Group continues to hone its malware capabilities and tradecraft, while keeping the foundations of Dream Job largely intact in attacks aimed at critical sectors across the world.
organisation
Vulnerability / Cyber Espionage
Vulnerability / Cyber Espionage
The North Korean threat actor known as
Lazarus Group
has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.
organisation
Microsoft Windows
Vulnerability / Cyber Espionage
The North Korean threat actor known as
Lazarus Group
has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.
organisation
ESET
ESET previously
tracked
compromises related to the campaign in India, Poland, the U.K. and most recently Italy.
organisation
Lockheed
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls.
The activity, per Check Point Research, is part of
Operation Dream Job
, a long-running cyber espionage and social engineering campaign orchestrated by Pyongyang-backed hackers to target professionals worldwide with fake-but-compelling job offers at firms like Lockheed Martin and Enveil to steal sensitive data and install malware by approaching them on platforms like LinkedIn, pretending to be recruiters in an attempt to build trust.
A Check Point report
released
on Tuesday said Lazarus Group hackers impersonated recruiters for Lockheed Martin and privacy-tech firm Enveil, contacting people on LinkedIn and other sites before sending candidates malicious PDF files.
Figure 2 – PDF decoy impersonating Lockheed Martin job description.
organisation
Check Point Research
Check Point Research has uncovered a new wave of
Operation Dream Job
, the long-running North Korean campaign that lures defense and aerospace professionals with convincing fake job offers.
Key Points
Check Point Research is tracking a long‑running campaign called
Operation Dream Job
, targeting organizations worldwide, with a particular focus on the defense sector.
The activity, per Check Point Research, is part of
Operation Dream Job
, a long-running cyber espionage and social engineering campaign orchestrated by Pyongyang-backed hackers to target professionals worldwide with fake-but-compelling job offers at firms like Lockheed Martin and Enveil to steal sensitive data and install malware by approaching them on platforms like LinkedIn, pretending to be recruiters in an attempt to build trust.
Check Point Research says Lazarus used the zero-day in its Operation Dream Job campaign.
organisation
Infection Chain
The
Infection Chain
The
Operation Dream Job
campaign begins with targeted spear-phishing lures centered on attractive job opportunities at well-known companies in the defense, aerospace, and aviation industries.
infrastructure
Roundcube
The threat actor’s decision to rely on compromised Roundcube instances and content management system (CMS) servers for C2 reflects an operational approach well suited to highly monitored defense-sector environments, where network activity may be closely inspected by organizational security teams as well as government and national cybersecurity authorities.
Check Point's analysis revealed that the hackers have also deployed a new backdoor called Troy that supports 17 commands, including the following:
System and process reconnaissance
File upload, download, deletion, and archive-based exfiltration
Hidden command execution
Remote process termination
In-memory DLL injection
Configuration and beacon timing changes
Check Point also reported observing scans targeting vulnerable Roundcube installations, which were subsequently compromised with a new PHP web shell dubbed RelayShell.
The C2 infrastructure is built from compromised Roundcube webmail installations and WordPress sites, many vulnerable to CVE-2025-49113, infected with a previously undocumented PHP webshell called RelayShell.
Command and Control on Borrowed Servers
The group ran its infrastructure almost entirely on machines it did not own, using Roundcube webmail servers exploited through
CVE-2025-49113
with credentials likely sourced from dark web leaks, alongside compromised PrestaShop sites.
The attacker likely used leaked credentials to authenticate to Roundcube before exploiting
CVE-2025-49113
, an authenticated PHP object-deserialization vulnerability, to obtain remote code execution.
Many of the Roundcube servers have been found to be vulnerable to
CVE-2025-49113
, with the attackers leveraging it to infect them with a previously undocumented PHP web shell codenamed RelayShell to enable the exchange of commands and responses in the form of text files.
Lazarus also used
CVE-2025-49113
to exploit vulnerable
Roundcube
webmail servers.
The majority of the Roundcube servers we analyzed were running versions vulnerable to
CVE-2025-49113
, a critical PHP Object Deserialization vulnerability that can lead to remote code execution (RCE).
We assess that the threat actor likely leveraged these credentials to authenticate to the affected Roundcube instances before exploiting
CVE-2025-49113
to deploy
RelayShell
web shells, which subsequently serve as a C2 relay mechanism.
For organizations running public-facing Roundcube or CMS installations, the secondary risk is becoming part of the relay infrastructure rather than the intended target: the servers used in this campaign were compromised through leaked credentials and a known unpatched vulnerability, not anything exotic.
In this case, the attacker abused legitimate web infrastructure (compromised Roundcube instances) to hide malicious communications.
The domain names are listed below -
envell[.]xyz
enveil[.]online
uxtramine[.]org
What's notable is that the campaign, instead of spinning up its own bespoke infrastructure, hijacks legitimate but compromised WordPress and SharePoint websites and vulnerable Roundcube webmail servers for use as ForestTiger command-and-control (C2) servers, thereby making it a lot more challenging to differentiate it from normal web traffic.
The attackers’ command-and-control infrastructure consists of compromised
Roundcube
and
WordPress
servers hosting
RelayShell
, a new PHP webshell that repurposes compromised web servers as relay nodes.
In more recent campaigns, the threat actor appears to have
shifted
toward using
compromised Roundcube webmail servers
as C2 infrastructure.
Exploitation of this vulnerability requires authentication with valid Roundcube credentials.
organisation
North Korean
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job.
organisation
Automox
Automox CTO Jason Kikta noted that the same component was previously exploited in 2024 by the Lazarus Group, an infamous hacking operation run out of North Korea’s Reconnaissance General Bureau.
organisation
Reconnaissance General Bureau
Automox CTO Jason Kikta noted that the same component was previously exploited in 2024 by the Lazarus Group, an infamous hacking operation run out of North Korea’s Reconnaissance General Bureau.
organisation
FudModule
Researchers at cybersecurity company Check Point, tracking the latest variant of Operation Dream Job, found that Lazarus incorporated an exploit for CVE-2026-68820 that specifically supported Windows 11 builds 26100 and 26200 into a new version of the FudModule kernel-mode rootkit to elevate privileges.
What arrived through the handshake was FudModule, Lazarus's kernel rootkit, in a build Check Point tracks as v3.1.It disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger and blinds 94 Event Tracing for Windows (ETW) providers.
MISTPEN, for its part, loads at least four different modules -
GetInfoPlugin
("Release_GetInfoPlugin_x64.dll"), to profile the host and exfiltrate the collected information as a single wide-character string
PvPlugin
("Release_PvPlugin_x64.dll"), to collect host reconnaissance data and details about running processes
OneScreenCapture
("OneScreenCapture64.dll"), to take screenshots of the current desktop, including all monitors, and transmit them as JPEG images
LPE (local privilege escalation) loader
, which gathers host information, generates new key material using the ML-KEM post-quantum key encapsulation algorithm, and uses the negotiated key during the handshake process to decrypt and run FudModule.
During the intrusion, the threat actor exploited
CVE-2026-68820
, a zero-day vulnerability in the Microsoft
AFD.sys
driver, to deploy a new version of
FudModule
, Lazarus’ kernel-mode rootkit.
organisation
CVE-2026
Researchers at cybersecurity company Check Point, tracking the latest variant of Operation Dream Job, found that Lazarus incorporated an exploit for CVE-2026-68820 that specifically supported Windows 11 builds 26100 and 26200 into a new version of the FudModule kernel-mode rootkit to elevate privileges.
CVE-2026-62893 hits Windows Deployment Services TFTP server, TFTP has no authentication, runs on UDP port 69, and any WDS server doing PXE boot is exposed.
Check Point Research
said CVE-2026-68820 is a use-after-free in afd.sys, the
Ancillary Function Driver for WinSock
and a kernel-side component of Windows networking.
During the intrusion, the threat actor exploited
CVE-2026-68820
, a zero-day vulnerability in the Microsoft
AFD.sys
driver, to deploy a new version of
FudModule
, Lazarus’ kernel-mode rootkit.
organisation
Enveil
The activity, per Check Point Research, is part of
Operation Dream Job
, a long-running cyber espionage and social engineering campaign orchestrated by Pyongyang-backed hackers to target professionals worldwide with fake-but-compelling job offers at firms like Lockheed Martin and Enveil to steal sensitive data and install malware by approaching them on platforms like LinkedIn, pretending to be recruiters in an attempt to build trust.
Victims are instructed to download SecurityPDF, a trojanized PDF viewer, from one of several websites impersonating Enveil, a legitimate privacy technology company with no actual connection to the attack.
In this infection chain, victims receive fraudulent job offers impersonating
Enveil, a
Privacy Enhancing Technology company
,
and are instructed to download an encrypted ZIP archive containing two files:
SecurityPDF
– a trojanized PDF viewer that has been modified to extract and execute an encrypted payload from specially crafted PDF documents.
organisation
LinkedIn
The activity, per Check Point Research, is part of
Operation Dream Job
, a long-running cyber espionage and social engineering campaign orchestrated by Pyongyang-backed hackers to target professionals worldwide with fake-but-compelling job offers at firms like Lockheed Martin and Enveil to steal sensitive data and install malware by approaching them on platforms like LinkedIn, pretending to be recruiters in an attempt to build trust.
organisation
PDF
In the latest variant of the
Operation Dream Job
campaign, the threat actor distributed
SecurityPDF
, a modified PDF viewer designed to open attacker-crafted PDF documents and execute a new backdoor which we named
Troy
.
A Check Point report
released
on Tuesday said Lazarus Group hackers impersonated recruiters for Lockheed Martin and privacy-tech firm Enveil, contacting people on LinkedIn and other sites before sending candidates malicious PDF files.
Those sites distributed a trojanized PDF viewer that runs a payload hidden inside crafted documents, delivering Troy, a previously undocumented backdoor supporting 17 operator commands.
As observed in prior campaign waves, victims are lured through bogus recruiter messages and tricked into opening a malicious PDF or installing a trojanized PDF viewer, which is then used to install a new backdoor called Troy that grants remote access to the compromised machine.
In the first, victims download an encrypted archive containing a legitimate signed PDF viewer and a malicious DLL.
organisation
YARA
We believe the technical details presented in this research will help defenders identify, detect, and disrupt future Operation Dream Job campaigns.
IOCs
DLL Loader\Dropper
2b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca8
3a02d0d798e8d35555776886d92b20ff38a101c9ef7e0eebc8ce5d259516525a
92106b0c62a0a42678232f8273f030b2d3c8e92efce81b98b9eec70cfe98afa1
396192d92d17ace1a521f1351eeeba2825e60badd0d799cc5c338e4934b3c82c
f7e620134ca935067797ab957317b346ce0df84a4e9b9ca54a6acc9b75afda4d
75b93a7103b0562f6497d30052c0c5cf7aa58c1bf0e9297022b74469a7f096f1
a45144d22cac70a45d71cf4dffa4efbc373658779a56cf1300d6ac863d6cc7e2
1de949c71efcfb0ffc41f33d38833dbc4b082075b1a540fc68c18c535d7ad86c
4c9b804d6155b29f1e27a9ffe531e10bc42a7bdab42f905b50146bf2026768d9
29e24c007549e51319ff3aee011da6f9f93568e8c85a5ad69c9e53bd3f4533a2
4ebdce2f47c23ff8c9e8e80c8b5239c7a5764da31cd3ab8f0505926890adc105
c2aa28bb5e2a749c693712008276f311edd912f689371ef9e8a1ee5fb4167461
MISTPEN
2db25ac41a66aa523c79e23e00443573530dd7bd82b8371bcc87bd7232e141eb
5278ee922838352f1480a73e971161017d643a80b7ec22bf725897dfd088696d
b4082d21070d9ddf53fde4ea22524d09e41ec9826ce63cef3c6235e458d21afb
fb3fc5626f68677fb1269a2fefbe70e719211b4065e836ab92e06a8210139a2d
ea7056f2bf36c66a61ff787ff5be975a85f534c3c5ca178791dac2504db2c619
13d10bc99f7f7abe7ee0902be87920b73b2ea41bd9683dbfcad340dacbcdef79
4fd32432341dfcf54d0517a6bbc38e5d265be70933493e4183c2a340cdde9a2d
4dd792c9f672bbdcc8d363d745994efe90f4ffc5fdc2c059c8e379a48ad6a68a
ba96c603e44046de703c67b2c3b7e4ca974afef7b437a0244418bc4edc781bb7
ForestTiger
72dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289
231b1ef8b95bf77887d5377e2a60f649035e78f543af1b82877db36a5759d858
6da9b1e6f3315ceb77dd14a937a26cc3602bf6a7e2c2ecafb3c65ce5319837be
a0578a2b7821d7e2c573530648f26d7a0d98b373ab24fb7f0c792736761e542d
82268052f94df6f4870d02e57b18d4c54136cc7a8c8d80ad162631f99462c943
FudModule
3b6378df8442e63a6ed7317075913e4720847a510d95022d4a8347b2637c245d
PDF Payload
a673ae661593c0de9bbb815593b816a6853dad6d55ad5042d2ef1875cd13d6e7
8ce6c29f92dc45b1474417cbdff4ed0c18e58fa63e3a071ee9f85aa9d2aac07c
acb97cec84e08b89f41967a24e965d1fd2c51751cef158f7aa35bb4306b87b97
3601060c62edeeaa49def6a13be6e126e1024ce011faad4e2d9f585ccf6bd5a6
fecf12088843801215898442bd1ff3e266f29d14e29a94780e857f69c4915d6b
d578c28c9afe7457a0d81f6701332ef8197e8f7468de654935fb29a50ea66459
SecurityPDF.exe
743172aab606974b054a64561534ae66baa3a840657f79d7c6fa18350e8d45d1
db3d69b7eeda2e35e23006bf4b7e206281fce809584207214fc213f9bc30376d
Troy Backdoor
590fb6ae19480d694e08ee85859cad8066f2f87e7e5abba2960c6d115e1615d6
68d4fba7b1300a59cd6212c08910a260cd71b40cd9f51cac933030a68faac0bb
a738059ce07c951c31ab2da3d93d8f69bff32f9b7d933dbf5943441b9cc99075
RelayShell
21c3ad4838c4324bc5f081021da5fb2e9073d0c9304087811c21eb47c9e22762
cc4e06aa378a190f71384c03023bb3d18a6d66e297d46701220e132963d2e222
SecurityPDF Website & Troy C2
envell[.]xyz
enveil[.]online
uxtramine[.]org
135.181.67[.]203
135.181.185[.]158
YARA – RelayShell Webshell
rule lazarus_relayshell
{
Check Point's report shares a list of indicators of compromise related to the attacks, as well as a YARA rule to help detect the RelayShell webshell.
organisation
SecurityPDF Website & Troy
We believe the technical details presented in this research will help defenders identify, detect, and disrupt future Operation Dream Job campaigns.
IOCs
DLL Loader\Dropper
2b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca8
3a02d0d798e8d35555776886d92b20ff38a101c9ef7e0eebc8ce5d259516525a
92106b0c62a0a42678232f8273f030b2d3c8e92efce81b98b9eec70cfe98afa1
396192d92d17ace1a521f1351eeeba2825e60badd0d799cc5c338e4934b3c82c
f7e620134ca935067797ab957317b346ce0df84a4e9b9ca54a6acc9b75afda4d
75b93a7103b0562f6497d30052c0c5cf7aa58c1bf0e9297022b74469a7f096f1
a45144d22cac70a45d71cf4dffa4efbc373658779a56cf1300d6ac863d6cc7e2
1de949c71efcfb0ffc41f33d38833dbc4b082075b1a540fc68c18c535d7ad86c
4c9b804d6155b29f1e27a9ffe531e10bc42a7bdab42f905b50146bf2026768d9
29e24c007549e51319ff3aee011da6f9f93568e8c85a5ad69c9e53bd3f4533a2
4ebdce2f47c23ff8c9e8e80c8b5239c7a5764da31cd3ab8f0505926890adc105
c2aa28bb5e2a749c693712008276f311edd912f689371ef9e8a1ee5fb4167461
MISTPEN
2db25ac41a66aa523c79e23e00443573530dd7bd82b8371bcc87bd7232e141eb
5278ee922838352f1480a73e971161017d643a80b7ec22bf725897dfd088696d
b4082d21070d9ddf53fde4ea22524d09e41ec9826ce63cef3c6235e458d21afb
fb3fc5626f68677fb1269a2fefbe70e719211b4065e836ab92e06a8210139a2d
ea7056f2bf36c66a61ff787ff5be975a85f534c3c5ca178791dac2504db2c619
13d10bc99f7f7abe7ee0902be87920b73b2ea41bd9683dbfcad340dacbcdef79
4fd32432341dfcf54d0517a6bbc38e5d265be70933493e4183c2a340cdde9a2d
4dd792c9f672bbdcc8d363d745994efe90f4ffc5fdc2c059c8e379a48ad6a68a
ba96c603e44046de703c67b2c3b7e4ca974afef7b437a0244418bc4edc781bb7
ForestTiger
72dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289
231b1ef8b95bf77887d5377e2a60f649035e78f543af1b82877db36a5759d858
6da9b1e6f3315ceb77dd14a937a26cc3602bf6a7e2c2ecafb3c65ce5319837be
a0578a2b7821d7e2c573530648f26d7a0d98b373ab24fb7f0c792736761e542d
82268052f94df6f4870d02e57b18d4c54136cc7a8c8d80ad162631f99462c943
FudModule
3b6378df8442e63a6ed7317075913e4720847a510d95022d4a8347b2637c245d
PDF Payload
a673ae661593c0de9bbb815593b816a6853dad6d55ad5042d2ef1875cd13d6e7
8ce6c29f92dc45b1474417cbdff4ed0c18e58fa63e3a071ee9f85aa9d2aac07c
acb97cec84e08b89f41967a24e965d1fd2c51751cef158f7aa35bb4306b87b97
3601060c62edeeaa49def6a13be6e126e1024ce011faad4e2d9f585ccf6bd5a6
fecf12088843801215898442bd1ff3e266f29d14e29a94780e857f69c4915d6b
d578c28c9afe7457a0d81f6701332ef8197e8f7468de654935fb29a50ea66459
SecurityPDF.exe
743172aab606974b054a64561534ae66baa3a840657f79d7c6fa18350e8d45d1
db3d69b7eeda2e35e23006bf4b7e206281fce809584207214fc213f9bc30376d
Troy Backdoor
590fb6ae19480d694e08ee85859cad8066f2f87e7e5abba2960c6d115e1615d6
68d4fba7b1300a59cd6212c08910a260cd71b40cd9f51cac933030a68faac0bb
a738059ce07c951c31ab2da3d93d8f69bff32f9b7d933dbf5943441b9cc99075
RelayShell
21c3ad4838c4324bc5f081021da5fb2e9073d0c9304087811c21eb47c9e22762
cc4e06aa378a190f71384c03023bb3d18a6d66e297d46701220e132963d2e222
SecurityPDF Website & Troy C2
envell[.]xyz
enveil[.]online
uxtramine[.]org
135.181.67[.]203
135.181.185[.]158
YARA – RelayShell Webshell
rule lazarus_relayshell
{
infrastructure
3.1
MISTPEN then runs reconnaissance modules, triggers the AFD.sys exploit to achieve SYSTEM privileges, and deploys
ForestTiger
, a well-documented Lazarus backdoor, along with an updated version of the group’s kernel-mode rootkit,
FudModule
3.1, which can now tamper with Windows Smart App Control to bypass software verification.
The newer version, called FudModule 3.1, improves upon its predecessor by allowing it to tamper with a Windows feature called
Smart App Control
designed to verify if a program is safe to run.
organisation
FudModule
3.1
MISTPEN then runs reconnaissance modules, triggers the AFD.sys exploit to achieve SYSTEM privileges, and deploys
ForestTiger
, a well-documented Lazarus backdoor, along with an updated version of the group’s kernel-mode rootkit,
FudModule
3.1, which can now tamper with Windows Smart App Control to bypass software verification.
organisation
Troy
This iteration is more dangerous than previous versions: it includes a previously unknown Windows vulnerability now patched as
CVE-2026-68820
, a newly documented backdoor called Troy, and command infrastructure built almost entirely from legitimate servers the attackers didn’t build, they hijacked them.
Once authenticated, Troy collects host information and registers the victim by sending a client identifier and a system profile containing the user profile directory, account name, Windows version, local IPv4 address, and current working directory.
Check Point's analysis revealed that the hackers have also deployed a new backdoor called Troy that supports 17 commands, including the following:
System and process reconnaissance
File upload, download, deletion, and archive-based exfiltration
Hidden command execution
Remote process termination
In-memory DLL injection
Configuration and beacon timing changes
Check Point also reported observing scans targeting vulnerable Roundcube installations, which were subsequently compromised with a new PHP web shell dubbed RelayShell.
Those sites distributed a trojanized PDF viewer that runs a payload hidden inside crafted documents, delivering Troy, a previously undocumented backdoor supporting 17 operator commands.
As observed in prior campaign waves, victims are lured through bogus recruiter messages and tricked into opening a malicious PDF or installing a trojanized PDF viewer, which is then used to install a new backdoor called Troy that grants remote access to the compromised machine.
organisation
EDR
“The attackers used a previously unknown vulnerability in Windows (CVE-2026-68820) to gain full control of infected computers and evade EDR visibility.
During the operation, the threat actor deployed a new version of the
FudModule
rootkit, exploiting a zero-day local privilege escalation (LPE) vulnerability in the Windows
AFD.sys
driver, to obtain
SYSTEM
privileges and disable EDR visibility.
According to the researchers, the latest version of the rootkit features previously documented capabilities such as disabling EDR telemetry and interfering with security products, while also adding Smart App Control tampering.
organisation
CVE-2026-68820
CVE-2026-68820 is a use-after-free race condition in AFD.sys, the driver handling network sockets in the Windows kernel, and was the only flaw in this the
August Patch Tuesday
release Microsoft flagged as under active exploitation.
organisation
Check Point
What arrived through the handshake was FudModule, Lazarus's kernel rootkit, in a build Check Point tracks as v3.1.It disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger and blinds 94 Event Tracing for Windows (ETW) providers.
Check Point's analysis revealed that the hackers have also deployed a new backdoor called Troy that supports 17 commands, including the following:
System and process reconnaissance
File upload, download, deletion, and archive-based exfiltration
Hidden command execution
Remote process termination
In-memory DLL injection
Configuration and beacon timing changes
Check Point also reported observing scans targeting vulnerable Roundcube installations, which were subsequently compromised with a new PHP web shell dubbed RelayShell.
Check Point reported the issue to Microsoft, which released a fix before this research was published” reads the
report
published by Check Point Research.
organisation
ETW
What arrived through the handshake was FudModule, Lazarus's kernel rootkit, in a build Check Point tracks as v3.1.It disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger and blinds 94 Event Tracing for Windows (ETW) providers.
The hardcoded ETW provider kill-list: its 94 GUIDs match the first 94 entries of Gen’s published 95-GUID list, in identical order.
organisation
Windows Ancillary Function
Microsoft says that the vulnerability is a "use-after-free in Windows Ancillary Function Driver for WinSock (AFD.sys)" that allows an attacker to increase their local privileges.
“Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.”
reads the advisory
.
organisation
FudModule 3.1
The newer version, called FudModule 3.1, improves upon its predecessor by allowing it to tamper with a Windows feature called
Smart App Control
designed to verify if a program is safe to run.
organisation
Winsock
“Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.”
reads the advisory
.
The actively exploited zero day (CVE-2026-68820) is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock.
Check Point Research
said CVE-2026-68820 is a use-after-free in afd.sys, the
Ancillary Function Driver for WinSock
and a kernel-side component of Windows networking.
The vulnerability impacts Winsock, a tool that acts as a bridge allowing web browsers to connect to the internet.
organisation
Windows Deployment Services
CVE-2026-62893 hits Windows Deployment Services TFTP server, TFTP has no authentication, runs on UDP port 69, and any WDS server doing PXE boot is exposed.
They affect Windows DNS Server, Windows Deployment Services, Microsoft's implementation of the QUIC transport protocol, and High Performance Computing (HPC) Pack, and each carries a CVSS score of 9.8.
organisation
TFTP
CVE-2026-62893 hits Windows Deployment Services TFTP server, TFTP has no authentication, runs on UDP port 69, and any WDS server doing PXE boot is exposed.
organisation
WDS
CVE-2026-62893 hits Windows Deployment Services TFTP server, TFTP has no authentication, runs on UDP port 69, and any WDS server doing PXE boot is exposed.
Prioritize exposed DNS, WDS, QUIC, and HPC services behind it, then confirm on-premises SharePoint farms have the July authentication-bypass fix and the August RCE fix.
organisation
PXE
CVE-2026-62893 hits Windows Deployment Services TFTP server, TFTP has no authentication, runs on UDP port 69, and any WDS server doing PXE boot is exposed.
organisation
Windows User Profile Service
Two publicly disclosed bugs — CVE-2026-62832 in Windows User Profile Service and CVE-2026-72971 in the Container Isolation FS Filter Driver — are also in this release, with the User Profile Service flaw considered likely to see exploitation.
organisation
the Container Isolation FS Filter
Two publicly disclosed bugs — CVE-2026-62832 in Windows User Profile Service and CVE-2026-72971 in the Container Isolation FS Filter Driver — are also in this release, with the User Profile Service flaw considered likely to see exploitation.
organisation
the User Profile Service
Two publicly disclosed bugs — CVE-2026-62832 in Windows User Profile Service and CVE-2026-72971 in the Container Isolation FS Filter Driver — are also in this release, with the User Profile Service flaw considered likely to see exploitation.
organisation
the Windows Ancillary Function
The actively exploited zero day (CVE-2026-68820) is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock.
organisation
CVE-2026-62832
CVE-2026-62832 is an Elevation of Privilege (EoP) vulnerability in the Windows User Profile Service which could allow an authenticated local attacker to elevate privileges.
organisation
the Windows User Profile Service
CVE-2026-62832 is an Elevation of Privilege (EoP) vulnerability in the Windows User Profile Service which could allow an authenticated local attacker to elevate privileges.
organisation
Windows Container Isolation FS
The second publicly disclosed zero day which has yet to be exploited in the wild is CVE-2026-72971: a Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability.
organisation
Microsoft Patches
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack.
organisation
Microsoft
Swati Khandelwal
Aug 11, 2026
Vulnerability / Windows Security
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.
During the intrusion, the threat actor exploited
CVE-2026-68820
, a zero-day vulnerability in the Microsoft
AFD.sys
driver, to deploy a new version of
FudModule
, Lazarus’ kernel-mode rootkit.
Check Point reported the issue to Microsoft, which released a fix before this research was published” reads the
report
published by Check Point Research.
The bug was the only vulnerability in Microsoft’s
Patch Tuesday release
that the company confirmed is being used in real-world attacks.
Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery.
Microsoft addressed the flaw in this month's
Patch Tuesday security updates
, marking it as
actively exploited in the wild
.
organisation
Vulnerability / Windows Security
Swati Khandelwal
Aug 11, 2026
Vulnerability / Windows Security
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.
organisation
CVSS
They affect Windows DNS Server, Windows Deployment Services, Microsoft's implementation of the QUIC transport protocol, and High Performance Computing (HPC) Pack, and each carries a CVSS score of 9.8.
Microsoft says it is actively exploited, although its CVSS assessment lists exploit maturity as “Unproven.”
organisation
Put CVE-2026-68820
Put CVE-2026-68820 at the top for Windows systems where an attacker already has code running and could use the flaw to reach SYSTEM.
organisation
LPE
During the operation, the threat actor deployed a new version of the
FudModule
rootkit, exploiting a zero-day local privilege escalation (LPE) vulnerability in the Windows
AFD.sys
driver, to obtain
SYSTEM
privileges and disable EDR visibility.
MISTPEN, for its part, loads at least four different modules -
GetInfoPlugin
("Release_GetInfoPlugin_x64.dll"), to profile the host and exfiltrate the collected information as a single wide-character string
PvPlugin
("Release_PvPlugin_x64.dll"), to collect host reconnaissance data and details about running processes
OneScreenCapture
("OneScreenCapture64.dll"), to take screenshots of the current desktop, including all monitors, and transmit them as JPEG images
LPE (local privilege escalation) loader
, which gathers host information, generates new key material using the ML-KEM post-quantum key encapsulation algorithm, and uses the negotiated key during the handshake process to decrypt and run FudModule.
organisation
PvPlugin
OsInfo: <Windows product name> <build_number>.<UBR>
PvPlugin – Process List Module
This module is a 64-bit Windows DLL internally named
Release_PvPlugin_x64.dll
.
organisation
the Windows Ancillary Function Driver
The module targets
afd.sys
, the Windows Ancillary Function Driver, a part of the Windows kernel that is in charge of managing and handling sockets in Windows.
organisation
ML-KEM
MISTPEN, for its part, loads at least four different modules -
GetInfoPlugin
("Release_GetInfoPlugin_x64.dll"), to profile the host and exfiltrate the collected information as a single wide-character string
PvPlugin
("Release_PvPlugin_x64.dll"), to collect host reconnaissance data and details about running processes
OneScreenCapture
("OneScreenCapture64.dll"), to take screenshots of the current desktop, including all monitors, and transmit them as JPEG images
LPE (local privilege escalation) loader
, which gathers host information, generates new key material using the ML-KEM post-quantum key encapsulation algorithm, and uses the negotiated key during the handshake process to decrypt and run FudModule.
infrastructure
7.0
The flaw is tracked as
CVE-2026-68820
(CVSS score: 7.0) and is the only one in this month's release Microsoft flags as under active exploitation.
organisation
PHP
Check Point's analysis revealed that the hackers have also deployed a new backdoor called Troy that supports 17 commands, including the following:
System and process reconnaissance
File upload, download, deletion, and archive-based exfiltration
Hidden command execution
Remote process termination
In-memory DLL injection
Configuration and beacon timing changes
Check Point also reported observing scans targeting vulnerable Roundcube installations, which were subsequently compromised with a new PHP web shell dubbed RelayShell.
The C2 infrastructure is built from compromised Roundcube webmail installations and WordPress sites, many vulnerable to CVE-2025-49113, infected with a previously undocumented PHP webshell called RelayShell.
Many of the Roundcube servers have been found to be vulnerable to
CVE-2025-49113
, with the attackers leveraging it to infect them with a previously undocumented PHP web shell codenamed RelayShell to enable the exchange of commands and responses in the form of text files.
Each hosts RelayShell, a previously undocumented PHP webshell that acts as a message relay rather than a conventional command shell, passing traffic between operator and victim through session files.
The compromised servers were infected with
RelayShell
, a PHP webshell that repurposes compromised web servers as relay nodes within the attacker’s command-and-control infrastructure.
organisation
RelayShell
Check Point's analysis revealed that the hackers have also deployed a new backdoor called Troy that supports 17 commands, including the following:
System and process reconnaissance
File upload, download, deletion, and archive-based exfiltration
Hidden command execution
Remote process termination
In-memory DLL injection
Configuration and beacon timing changes
Check Point also reported observing scans targeting vulnerable Roundcube installations, which were subsequently compromised with a new PHP web shell dubbed RelayShell.
The C2 infrastructure is built from compromised Roundcube webmail installations and WordPress sites, many vulnerable to CVE-2025-49113, infected with a previously undocumented PHP webshell called RelayShell.
Many of the Roundcube servers have been found to be vulnerable to
CVE-2025-49113
, with the attackers leveraging it to infect them with a previously undocumented PHP web shell codenamed RelayShell to enable the exchange of commands and responses in the form of text files.
Each hosts RelayShell, a previously undocumented PHP webshell that acts as a message relay rather than a conventional command shell, passing traffic between operator and victim through session files.
The compromised servers were infected with
RelayShell
, a PHP webshell that repurposes compromised web servers as relay nodes within the attacker’s command-and-control infrastructure.
organisation
DLL
Check Point's analysis revealed that the hackers have also deployed a new backdoor called Troy that supports 17 commands, including the following:
System and process reconnaissance
File upload, download, deletion, and archive-based exfiltration
Hidden command execution
Remote process termination
In-memory DLL injection
Configuration and beacon timing changes
Check Point also reported observing scans targeting vulnerable Roundcube installations, which were subsequently compromised with a new PHP web shell dubbed RelayShell.
In the first, victims download an encrypted archive containing a legitimate signed PDF viewer and a malicious DLL.
Two different parallel infection sequences have been detected as part of the latest attacks -
DLL side-loading
, in which victims are instructed to download an encrypted archive that's used to trigger a DLL side-loading chain.
A malicious DLL that is loaded through DLL sideloading.
organisation
Microsoft Graph API
The downloader communicates with threat actor-controlled infrastructure using Microsoft Graph API and OneDrive to retrieve and run reconnaissance and persistence modules and trigger the "AFD.sys" driver exploit, before deploying
ForestTiger
(aka ScoringMathTea), which provides remote access to the host.
The DLL displays a convincing Lockheed Martin job description while silently loading
MISTPEN
, a lightweight downloader that communicates through Microsoft Graph API and OneDrive.
The executed payload is
MISTPEN
, a lightweight in-memory downloader that uses Microsoft Graph API to access OneDrive in order to retrieve additional modules and run them in memory.
organisation
OneDrive
The downloader communicates with threat actor-controlled infrastructure using Microsoft Graph API and OneDrive to retrieve and run reconnaissance and persistence modules and trigger the "AFD.sys" driver exploit, before deploying
ForestTiger
(aka ScoringMathTea), which provides remote access to the host.
The DLL displays a convincing Lockheed Martin job description while silently loading
MISTPEN
, a lightweight downloader that communicates through Microsoft Graph API and OneDrive.
The executed payload is
MISTPEN
, a lightweight in-memory downloader that uses Microsoft Graph API to access OneDrive in order to retrieve additional modules and run them in memory.
Four Keys and a Layered Handshake
Infection ran through MISTPEN, an in-memory downloader that communicates via attacker-controlled files on OneDrive using the Microsoft Graph API.
organisation
ForestTiger
The downloader communicates with threat actor-controlled infrastructure using Microsoft Graph API and OneDrive to retrieve and run reconnaissance and persistence modules and trigger the "AFD.sys" driver exploit, before deploying
ForestTiger
(aka ScoringMathTea), which provides remote access to the host.
Backdoor Deployment:
The final backdoor delivered by MISTPEN is the
ForestTiger
backdoor, a well-documented malware family widely attributed to the
Lazarus
threat group.
organisation
ScoringMathTea
The downloader communicates with threat actor-controlled infrastructure using Microsoft Graph API and OneDrive to retrieve and run reconnaissance and persistence modules and trigger the "AFD.sys" driver exploit, before deploying
ForestTiger
(aka ScoringMathTea), which provides remote access to the host.
organisation
SEO
In this campaign, the threat actor expanded its delivery method by leveraging impersonation websites and search engine optimization (SEO) techniques to distribute the trojanized applications, increasing its credibility and helping it evade some phishing-based detections.
organisation
CVE-2025-49113
The C2 infrastructure is built from compromised Roundcube webmail installations and WordPress sites, many vulnerable to CVE-2025-49113, infected with a previously undocumented PHP webshell called RelayShell.
Command and Control on Borrowed Servers
The group ran its infrastructure almost entirely on machines it did not own, using Roundcube webmail servers exploited through
CVE-2025-49113
with credentials likely sourced from dark web leaks, alongside compromised PrestaShop sites.
organisation
WordPress
The C2 infrastructure is built from compromised Roundcube webmail installations and WordPress sites, many vulnerable to CVE-2025-49113, infected with a previously undocumented PHP webshell called RelayShell.
The domain names are listed below -
envell[.]xyz
enveil[.]online
uxtramine[.]org
What's notable is that the campaign, instead of spinning up its own bespoke infrastructure, hijacks legitimate but compromised WordPress and SharePoint websites and vulnerable Roundcube webmail servers for use as ForestTiger command-and-control (C2) servers, thereby making it a lot more challenging to differentiate it from normal web traffic.
The attackers’ command-and-control infrastructure consists of compromised
Roundcube
and
WordPress
servers hosting
RelayShell
, a new PHP webshell that repurposes compromised web servers as relay nodes.
organisation
Command
Command and Control on Borrowed Servers
The group ran its infrastructure almost entirely on machines it did not own, using Roundcube webmail servers exploited through
CVE-2025-49113
with credentials likely sourced from dark web leaks, alongside compromised PrestaShop sites.
organisation
PrestaShop
Command and Control on Borrowed Servers
The group ran its infrastructure almost entirely on machines it did not own, using Roundcube webmail servers exploited through
CVE-2025-49113
with credentials likely sourced from dark web leaks, alongside compromised PrestaShop sites.
organisation
CVE-2025
The attacker likely used leaked credentials to authenticate to Roundcube before exploiting
CVE-2025-49113
, an authenticated PHP object-deserialization vulnerability, to obtain remote code execution.
Many of the Roundcube servers have been found to be vulnerable to
CVE-2025-49113
, with the attackers leveraging it to infect them with a previously undocumented PHP web shell codenamed RelayShell to enable the exchange of commands and responses in the form of text files.
Lazarus also used
CVE-2025-49113
to exploit vulnerable
Roundcube
webmail servers.
organisation
PHP Object Deserialization
The majority of the Roundcube servers we analyzed were running versions vulnerable to
CVE-2025-49113
, a critical PHP Object Deserialization vulnerability that can lead to remote code execution (RCE).
organisation
CMS
For organizations running public-facing Roundcube or CMS installations, the secondary risk is becoming part of the relay infrastructure rather than the intended target: the servers used in this campaign were compromised through leaked credentials and a known unpatched vulnerability, not anything exotic.
organisation
SharePoint
The domain names are listed below -
envell[.]xyz
enveil[.]online
uxtramine[.]org
What's notable is that the campaign, instead of spinning up its own bespoke infrastructure, hijacks legitimate but compromised WordPress and SharePoint websites and vulnerable Roundcube webmail servers for use as ForestTiger command-and-control (C2) servers, thereby making it a lot more challenging to differentiate it from normal web traffic.
The release also closes the RCE half of a SharePoint chain whose authentication bypass was fixed in July.
Compromised Infrastructure Used as ForestTiger C2
As previously reported, ForestTiger’s C2 infrastructure has historically relied primarily on compromised servers mainly running WordPress and SharePoint.
organisation
UAV
“The second chain is more recent and shares several characteristics with a campaign
described by ESET
against the UAV sector in 2025.
organisation
PDB
Its name comes from a PDB path embedded in the binary that Check Point also observed in earlier Lazarus samples.
The name
Troy
is derived from a PDB path embedded in the sample:
E:\HK\Tool_Module\Troy_Handle\1Troy_Create_Dll_Tool\x64\Release\Test_Dll.pdb
.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Lazarus)
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Microsoft Patch Tuesday)
infrastructure
17 unique server identifiers
We also identified
17 unique identifiers
, suggesting that at least 17 compromised servers were likely used as relay nodes during the campaign.
Check Point identified at least 17 unique server identifiers in this relay network, with operators connecting through commercial VPNs to further obscure their location.
Check Point found evidence of at least 17 compromised relay servers.
RelayShell commands
Source: Check Point
The researchers have identified at least 17 servers infected with RelayShell, based on the number of identifiers they retrieved.
organisation
Disney
Google
warned in 2022
that 250 people working for 10 different news media, domain registrars, web hosting providers and software vendors were targeted by the campaign, receiving malicious emails from fake recruiters claiming to be from Disney, Google and Oracle.
organisation
Google
Google
warned in 2022
that 250 people working for 10 different news media, domain registrars, web hosting providers and software vendors were targeted by the campaign, receiving malicious emails from fake recruiters claiming to be from Disney, Google and Oracle.
organisation
Oracle
Google
warned in 2022
that 250 people working for 10 different news media, domain registrars, web hosting providers and software vendors were targeted by the campaign, receiving malicious emails from fake recruiters claiming to be from Disney, Google and Oracle.
organisation
Operation DreamJob
Threat researchers at several companies have been
tracking
the Operation DreamJob campaign since 2020.
organisation
National Cyber Security Centre
On the eve of that surge, Britain’s National Cyber Security Centre
warned
that organizations needed to prepare for a new tempo in mitigating vulnerabilities.
organisation
Lazarus Used Post-Quantum Key Exchange
Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day.
organisation
Kyber/ML-KEM
It used them to generate fresh key material with Kyber/ML-KEM, the key encapsulation scheme NIST standardized in 2024 to
resist attack by quantum computers
, returning the encapsulated result before requesting the exploit itself, which it decrypted and ran in memory.
Session Key Generation
– Using the received public keys, the module generates new key material using the
Kyber/ML-KEM
algorithm and transmits the resulting encapsulated key material back to the C2.
LPE Deployment
– Finally, the module requests the encrypted LPE payload, decrypts it using the negotiated key, and executes it directly in memory with export
DestroyEnv
.
organisation
NIST
It used them to generate fresh key material with Kyber/ML-KEM, the key encapsulation scheme NIST standardized in 2024 to
resist attack by quantum computers
, returning the encapsulated result before requesting the exploit itself, which it decrypted and ran in memory.
organisation
GOST-CBC
Traffic through that channel carried a second encryption layer using GOST-CBC, on top of MISTPEN's own AES transport encryption.
organisation
AES
Traffic through that channel carried a second encryption layer using GOST-CBC, on top of MISTPEN's own AES transport encryption.
First
documented
by Mandiant in 2024, it functions as a lightweight downloader that uses the Microsoft Graph API to communicate through attacker-controlled files hosted on OneDrive and retrieve additional payloads
All files exchanged through OneDrive are encrypted with AES, using separate keys for uploads and downloads.
organisation
Mandiant
First
documented
by Mandiant in 2024, it functions as a lightweight downloader that uses the Microsoft Graph API to communicate through attacker-controlled files hosted on OneDrive and retrieve additional payloads
All files exchanged through OneDrive are encrypted with AES, using separate keys for uploads and downloads.
organisation
Smart App Control
Newly added is tampering with Smart App Control, resetting its policy state and forcing a code integrity reload.
organisation
Delivery
Delivery has also shifted.
organisation
JPEG
The bitmap is then converted to a JPEG image and Base64-encoded into a single wide-character string before being returned to MISTPEN for exfiltration.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
Backdoor Deployment:
Backdoor Deployment:
The final backdoor delivered by MISTPEN is the
ForestTiger
backdoor, a well-documented malware family widely attributed to the
Lazarus
threat group.
organisation
ForestTiger’s C2
Compromised Infrastructure Used as ForestTiger C2
As previously reported, ForestTiger’s C2 infrastructure has historically relied primarily on compromised servers mainly running WordPress and SharePoint.
infrastructure
2.0
The August updates also fix two CVEs in the TPM 2.0 reference implementation, one spoofing and one information disclosure.
organisation
DNS
Prioritize exposed DNS, WDS, QUIC, and HPC services behind it, then confirm on-premises SharePoint farms have the July authentication-bypass fix and the August RCE fix.
organisation
HPC
Prioritize exposed DNS, WDS, QUIC, and HPC services behind it, then confirm on-premises SharePoint farms have the July authentication-bypass fix and the August RCE fix.
CVE-2026-59124 is a CVSS 9.8 flaw in Microsoft HPC Pack that Microsoft itself rates as “exploitation more likely”, the Important severity rating reflects that HPC isn’t on by default, not that the bug is less dangerous.
organisation
Important
CVE-2026-59124 is a CVSS 9.8 flaw in Microsoft HPC Pack that Microsoft itself rates as “exploitation more likely”, the Important severity rating reflects that HPC isn’t on by default, not that the bug is less dangerous.
It carries the same 9.8 score but is rated Important rather than Critical because HPC Pack is not installed by default.
organisation
CVE-2026-59124
CVE-2026-59124, HPC Pack.
organisation
HPC Pack
CVE-2026-59124, HPC Pack.
organisation
Exchange
The Exchange bug, CVE-2026-62911, is an elevation of privilege flaw via authentication bypass that was demonstrated with working code at
Pwn2Own Berlin
.
organisation
Critical
Sixty-two are rated Critical.
July fixed the first half,
CVE-2026-55040
, a Critical authentication bypass scored at 9.1.
infrastructure
9.1
July fixed the first half,
CVE-2026-55040
, a Critical authentication bypass scored at 9.1.
organisation
Microsoft Fixes
Microsoft Fixes 400 Flaws on August Patch Tuesday.
organisation
RCE
Some 37 of RCE bugs were rated “critical” out of a total of 42 critical vulnerabilities this month.
August supplies the fix for the RCE component, identified as
CVE-2026-63520
.
data_breach
570 record
The figure is not quite as high as the record 570 issued in
July’s Patch Tuesday
but it will be a challenge to process for organizations without automated, risk-based patching programs.
organisation
ZDI
ZDI's “wormable” label describes the technical condition; it does not establish that a worm exists.
infrastructure
9.8 server
Microsoft flags it as actively exploited, which puts it ahead of the four 9.8 server RCEs here despite the lower score.
organisation
Functionality
Functionality removed from v3
The dedicated Microsoft Defender stage used to disable monitoring of
MsMpEng.exe
.
organisation
Microsoft Defender
Functionality removed from v3
The dedicated Microsoft Defender stage used to disable monitoring of
MsMpEng.exe
.
organisation
PPL
The PPL stripping functionality targeting AhnLab’s
asdsvc.exe
.
organisation
AhnLab
The PPL stripping functionality targeting AhnLab’s
asdsvc.exe
.
organisation
DLL Sideloading
Infection Chain 1: DLL Sideloading chain
organisation
PE DLL
MISTPEN’s primary capability is the reflective loading of PE DLL files directly into memory, enabling the deployment of additional payloads without touching disk.
organisation
the Process PID
For each running process, the module collects the Process PID, PPID, creation timestamp, associated domain and user, and process name.
organisation
PPID
For each running process, the module collects the Process PID, PPID, creation timestamp, associated domain and user, and process name.
organisation
RPC
It is loaded by an extended version of MISTPEN that provides it with an RPC buffer used for communication between the two components.
organisation
MISTPEN’s
In addition to MISTPEN’s AES-based transport encryption, the module encrypts all exchanged data using
GOST-CBC
with a randomly generated 16-byte session key.
data_breach
16 byte
In addition to MISTPEN’s AES-based transport encryption, the module encrypts all exchanged data using
GOST-CBC
with a randomly generated 16-byte session key.
organisation
Key Exchange
Key Exchange
– The module requests a set of four public keys from the C2 server.
organisation
the Microsoft Security Response Center
Disclosure timeline
Jul 28, 2026
: Issue reported to the Microsoft Security Response Center (MSRC).
organisation
MSRC
Disclosure timeline
Jul 28, 2026
: Issue reported to the Microsoft Security Response Center (MSRC).
organisation
WFP
The WFP stage, which is activated when Kaspersky is present and Symantec is absent.
organisation
Kaspersky
The WFP stage, which is activated when Kaspersky is present and Symantec is absent.
organisation
SuspendDefender
Only the orphaned string
SuspendDefender passed.
organisation
Troy Backdoor
The
Troy Backdoor
The
Troy
backdoor is a newly identified modular remote access trojan in
Lazarus’
arsenal.
organisation
Lazarus’
Troy Backdoor
The
Troy
backdoor is a newly identified modular remote access trojan in
Lazarus’
arsenal.
organisation
RWX
Figure 8 – Troy’s reflective DLL injection flow, showing remote RWX allocation, loader and payload writes, and execution through RtlCreateUserThread.
organisation
Compress-Archive
ZIPDOWNLOAD|<src>|<dst>
Archive and exfiltrate
Compresses a path with PowerShell
Compress-Archive
into a temporary archive, uploads it, then removes the archive.
organisation
Terminates
mem <dllpath> <pid>
In-memory DLL injection
Maps a DLL into a remote process using an embedded reflective loader, matching architecture before injecting.
pk <pid>
Process termination
Terminates a process by identifier and reports the outcome.
sleep <N>
One-shot delay
Pauses the implant for N minutes without changing the stored interval.
organisation
WMI
pvd
Process listing with command lines
Enumerates processes with session, owner and start time, enriched with full command lines retrieved over WMI.
organisation
PID
The configuration contains two values:
A backbone URL
A unique identifier (PID) assigned to the compromised server
RelayShell then immediately sends an HTTP POST request to the configured backbone URL using the unique identifier and authentication password.
organisation
WebShell
Figure 9 – WebShell contacting the backbone compromised server on new session creation.
organisation
Command Type
Description
Session
Command Type
Description
Session auth / selection
Scans existing
.ses
files, picks the latest session, and returns its data.
organisation
Check & cleanup
Check & cleanup
Updates configuration, deletes old session/log/temp files, and checks connectivity to the backbone URL.
organisation
File-Based Communication Channel
File-Based Communication Channel
August 25
Threat actors exploited a recently discovered Windows zero-day vulnerability to gain system access.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls.
“Rather than running their own servers, the attackers are hijacking legitimate but compromised websites and webmail servers to relay commands, making the malicious traffic harder to distinguish from normal activity”
The vulnerability, CVE-2026-68820, is the same actively exploited zero-day that Microsoft patched on August 11 as part of
Patch Tuesday
, a privilege escalation flaw in AFD.sys, the kernel driver underlying Windows Sockets.
MISTPEN then runs reconnaissance modules, triggers the AFD.sys exploit to achieve SYSTEM privileges, and deploys
ForestTiger
, a well-documented Lazarus backdoor, along with an updated version of the group’s kernel-mode rootkit,
FudModule
3.1, which can now tamper with Windows Smart App Control to bypass software verification.
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job.
This iteration is more dangerous than previous versions: it includes a previously unknown Windows vulnerability now patched as
CVE-2026-68820
, a newly documented backdoor called Troy, and command infrastructure built almost entirely from legitimate servers the attackers didn’t build, they hijacked them.
“The attackers used a previously unknown vulnerability in Windows (CVE-2026-68820) to gain full control of infected computers and evade EDR visibility.
Federal agencies were ordered to patch a Windows vulnerability used by North Korean hackers to target people applying to jobs in the defense and aerospace industry.
It's the one confirmed-exploited bug in the release, and it applies to every Windows endpoint you manage.
Two were publicly disclosed before the patches dropped, while one of which —
CVE-2026-68820
, affecting the Windows component that handles network connections — has been seen exploited in the wild.
Malware used by North Korea's Lazarus group negotiated its command channel using a post-quantum key exchange before pulling down a Windows zero-day exploit, in a campaign against defense and aerospace companies across Europe and India.
CVE-2026-68820 is a use-after-free race condition in AFD.sys, the driver handling network sockets in the Windows kernel, and was the only flaw in this the
August Patch Tuesday
release Microsoft flagged as under active exploitation.
What arrived through the handshake was FudModule, Lazarus's kernel rootkit, in a build Check Point tracks as v3.1.It disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger and blinds 94 Event Tracing for Windows (ETW) providers.
Lazarus hackers exploited Windows zero-day to target defense firms.
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign.
Microsoft says that the vulnerability is a "use-after-free in Windows Ancillary Function Driver for WinSock (AFD.sys)" that allows an attacker to increase their local privileges.
Researchers at cybersecurity company Check Point, tracking the latest variant of Operation Dream Job, found that Lazarus incorporated an exploit for CVE-2026-68820 that specifically supported Windows 11 builds 26100 and 26200 into a new version of the FudModule kernel-mode rootkit to elevate privileges.
Vulnerability / Cyber Espionage
The North Korean threat actor known as
Lazarus Group
has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.
The
attacks
have been found to exploit
CVE-2026-68820
(CVSS score: 7.0), a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys") that was patched by Microsoft as part of its Patch Tuesday updates for August 2026.
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor.
The newer version, called FudModule 3.1, improves upon its predecessor by allowing it to tamper with a Windows feature called
Smart App Control
designed to verify if a program is safe to run.
Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, GitHub Copilot, .NET, and a range of other components.
The actively exploited bug is
CVE-2026-68820
, a use-after-free flaw in afd.sys, the kernel-mode driver that underpins the Windows Sockets API.
CVE-2026-68820 is a Windows WinSock driver flaw that can let attackers execute code with SYSTEM-level privileges.
“Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.”
reads the advisory
.
CVE-2026-62878 is a critical Windows DNS Server flaw that allows remote, unauthenticated attackers to execute code with elevated privileges without user interaction.
CVE-2026-62893 hits Windows Deployment Services TFTP server, TFTP has no authentication, runs on UDP port 69, and any WDS server doing PXE boot is exposed.
Two publicly disclosed bugs — CVE-2026-62832 in Windows User Profile Service and CVE-2026-72971 in the Container Isolation FS Filter Driver — are also in this release, with the User Profile Service flaw considered likely to see exploitation.
The actively exploited zero day (CVE-2026-68820) is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock.
A locally authenticated attacker with low privileges could run a specially crafted application and trigger a race condition to gain system privileges and extensive control over a targeted Windows system.
CVE-2026-62832 is an Elevation of Privilege (EoP) vulnerability in the Windows User Profile Service which could allow an authenticated local attacker to elevate privileges.
The second publicly disclosed zero day which has yet to be exploited in the wild is CVE-2026-72971: a Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability.
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack.
Swati Khandelwal
Aug 11, 2026
Vulnerability / Windows Security
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.
The bug sits in a core Windows kernel driver that handles network socket operations.
They affect Windows DNS Server, Windows Deployment Services, Microsoft's implementation of the QUIC transport protocol, and High Performance Computing (HPC) Pack, and each carries a CVSS score of 9.8.
Check Point Research
said CVE-2026-68820 is a use-after-free in afd.sys, the
Ancillary Function Driver for WinSock
and a kernel-side component of Windows networking.
CVE-2026-62878, Windows DNS Server.
CVE-2026-62893, Windows Deployment Services.
Put CVE-2026-68820 at the top for Windows systems where an attacker already has code running and could use the flaw to reach SYSTEM.
During the operation, the threat actor deployed a new version of the
FudModule
rootkit, exploiting a zero-day local privilege escalation (LPE) vulnerability in the Windows
AFD.sys
driver, to obtain
SYSTEM
privileges and disable EDR visibility.
GetInfoPlugin – Host Reconnaissance Module
This module is a 64-bit Windows DLL internally named
Release_GetInfoPlugin_x64.dll
.
LPE loader
This module is a 64-bit Windows DLL that acts as a loader for a local privilege escalation (LPE) exploit module.
OsInfo: <Windows product name> <build_number>.<UBR>
PvPlugin – Process List Module
This module is a 64-bit Windows DLL internally named
Release_PvPlugin_x64.dll
.
OneScreenCapture – Screenshot Module
This module is a 64-bit Windows DLL internally named
OneScreenCapture64.dll,
it ****is responsible for capturing the current desktop (including all monitors) and returns the screenshot to its caller.
The module uses standard Windows
USER32
and
GDI
APIs to capture the virtual desktop into a bitmap.
The module targets
afd.sys
, the Windows Ancillary Function Driver, a part of the Windows kernel that is in charge of managing and handling sockets in Windows.
In the sample itself, we observed an explicit minimum-version check for
Windows 11
build 26100 (24H2)
, with explicit support also for
build 26200 (25H2)
.
However, testing on the latest fully patched Windows 11 system confirmed that the exploit targets a distinct, previously undocumented vulnerability, actively being used in the wild as a part of Operation ‘Dream Job’ since at least early July 2026.
Targeting
As mentioned before, this version only targets newer Windows builds 26100/26200, unlike the previous version that also targeted older ones.
Once authenticated, Troy collects host information and registers the victim by sending a client identifier and a system profile containing the user profile directory, account name, Windows version, local IPv4 address, and current working directory.
Metrics
infrastructure
3.1
Software Version
MISTPEN then runs reconnaissance modules, triggers the AFD.sys exploit to achieve SYSTEM privileges, and deploys
ForestTiger
, a well-documented Lazarus backdoor, along with an updated version of the group’s kernel-mode rootkit,
FudModule
3.1, which can now tamper with Windows Smart App Control to bypass software verification.
The newer version, called FudModule 3.1, improves upon its predecessor by allowing it to tamper with a Windows feature called
Smart App Control
designed to verify if a program is safe to run.
Metrics
infrastructure
Roundcube
Affected Product
The C2 infrastructure is built from compromised Roundcube webmail installations and WordPress sites, many vulnerable to CVE-2025-49113, infected with a previously undocumented PHP webshell called RelayShell.
For organizations running public-facing Roundcube or CMS installations, the secondary risk is becoming part of the relay infrastructure rather than the intended target: the servers used in this campaign were compromised through leaked credentials and a known unpatched vulnerability, not anything exotic.
Command and Control on Borrowed Servers
The group ran its infrastructure almost entirely on machines it did not own, using Roundcube webmail servers exploited through
CVE-2025-49113
with credentials likely sourced from dark web leaks, alongside compromised PrestaShop sites.
Check Point's analysis revealed that the hackers have also deployed a new backdoor called Troy that supports 17 commands, including the following:
System and process reconnaissance
File upload, download, deletion, and archive-based exfiltration
Hidden command execution
Remote process termination
In-memory DLL injection
Configuration and beacon timing changes
Check Point also reported observing scans targeting vulnerable Roundcube installations, which were subsequently compromised with a new PHP web shell dubbed RelayShell.
The attacker likely used leaked credentials to authenticate to Roundcube before exploiting
CVE-2025-49113
, an authenticated PHP object-deserialization vulnerability, to obtain remote code execution.
In this case, the attacker abused legitimate web infrastructure (compromised Roundcube instances) to hide malicious communications.
The domain names are listed below -
envell[.]xyz
enveil[.]online
uxtramine[.]org
What's notable is that the campaign, instead of spinning up its own bespoke infrastructure, hijacks legitimate but compromised WordPress and SharePoint websites and vulnerable Roundcube webmail servers for use as ForestTiger command-and-control (C2) servers, thereby making it a lot more challenging to differentiate it from normal web traffic.
Many of the Roundcube servers have been found to be vulnerable to
CVE-2025-49113
, with the attackers leveraging it to infect them with a previously undocumented PHP web shell codenamed RelayShell to enable the exchange of commands and responses in the form of text files.
The threat actor’s decision to rely on compromised Roundcube instances and content management system (CMS) servers for C2 reflects an operational approach well suited to highly monitored defense-sector environments, where network activity may be closely inspected by organizational security teams as well as government and national cybersecurity authorities.
Lazarus also used
CVE-2025-49113
to exploit vulnerable
Roundcube
webmail servers.
The attackers’ command-and-control infrastructure consists of compromised
Roundcube
and
WordPress
servers hosting
RelayShell
, a new PHP webshell that repurposes compromised web servers as relay nodes.
In more recent campaigns, the threat actor appears to have
shifted
toward using
compromised Roundcube webmail servers
as C2 infrastructure.
The majority of the Roundcube servers we analyzed were running versions vulnerable to
CVE-2025-49113
, a critical PHP Object Deserialization vulnerability that can lead to remote code execution (RCE).
Exploitation of this vulnerability requires authentication with valid Roundcube credentials.
We assess that the threat actor likely leveraged these credentials to authenticate to the affected Roundcube instances before exploiting
CVE-2025-49113
to deploy
RelayShell
web shells, which subsequently serve as a C2 relay mechanism.
Metrics
infrastructure
17
Unique Server Identifiers
Check Point identified at least 17 unique server identifiers in this relay network, with operators connecting through commercial VPNs to further obscure their location.
Check Point found evidence of at least 17 compromised relay servers.
RelayShell commands
Source: Check Point
The researchers have identified at least 17 servers infected with RelayShell, based on the number of identifiers they retrieved.
We also identified
17 unique identifiers
, suggesting that at least 17 compromised servers were likely used as relay nodes during the campaign.
Metrics
infrastructure
7.0
Software Version
The
attacks
have been found to exploit
CVE-2026-68820
(CVSS score: 7.0), a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys") that was patched by Microsoft as part of its Patch Tuesday updates for August 2026.
The flaw is tracked as
CVE-2026-68820
(CVSS score: 7.0) and is the only one in this month's release Microsoft flags as under active exploitation.
Metrics
infrastructure
2.0
Software Version
The August updates also fix two CVEs in the TPM 2.0 reference implementation, one spoofing and one information disclosure.
Metrics
data_breach
570
Record
The figure is not quite as high as the record 570 issued in
July’s Patch Tuesday
but it will be a challenge to process for organizations without automated, risk-based patching programs.
Metrics
infrastructure
9.1
Software Version
July fixed the first half,
CVE-2026-55040
, a Critical authentication bypass scored at 9.1.
Metrics
infrastructure
10
Server
Microsoft flags it as actively exploited, which puts it ahead of the four 9.8 server RCEs here despite the lower score.
Metrics
data_breach
16
Byte
In addition to MISTPEN’s AES-based transport encryption, the module encrypts all exchanged data using
GOST-CBC
with a randomly generated 16-byte session key.
Intelligence Sources
The Hacker News
2026-08-11
Zero Day Fans
2026-08-11
Infosecurity-Magazine
2026-08-12
Microsoft Fixes 400 Flaws on August Patch Tuesday
Infosecurity-Magazine
Security Affairs
2026-08-12
Infosecurity-Magazine
2026-08-12
Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
Infosecurity-Magazine
TheRecord
2026-08-12
The Hacker News
2026-08-12
BleepingComputer
2026-08-12
Lazarus hackers exploited Windows zero-day to target defense firms
BleepingComputer
TheRecord
2026-08-12
Security Affairs
2026-08-13
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Reset / Delete
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-13T11:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
129x
organisation
Identified Entity
Lockheed
entity
26x
timeline
Temporal Reference
August 11
date
13x
vulnerability
Exploited CVE
CVE-2026-68820
cve
11x
tactic
Cyber Operation Type
Privilege Escalation
tactic
7x
target region
Target Country
France
country
6x
industry
Targeted Sector
Defense
sector
6x
attribution
Attributing Entity
FBI
authority
6x
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
4x
infrastructure
Software Version
3.1
version
4x
target region
Target Region
DPRK
region
2x
source region
Origin Region
DPRK
region
2x
campaign
Campaign
Operation Dream Job
operation
2x
infrastructure
Affected Product
Windows
software
2x
source region
Origin Country
Korea, Democratic People's Republic of
country
2x
general metric
Rated Issues
62
rated issues
2x
general metric
Windows
11
windows
2x
general metric
Flaws
400
flaws
Contextual Telemetry
Context Block
33 METRICS
threat actor
APT Group
Lazarus Group
actor
general metric
Fudmodule
3
fudmodule
general metric
Operator
17
operator
infrastructure
Unique Server Identifiers
17
unique server identifiers
general metric
People
250
people
general metric
Different News Media
10
different news media
general metric
Security Vulnerabilities
419
security vulnerabilities
general metric
Vulnerabilities
137
vulnerabilities
general metric
Successive Breaking Releases
206
successive breaking releases
general metric
Event
94
event
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Attacks
7
attacks
general metric
Aug
12
aug
general metric
Reference
2
reference
general metric
Udp Port
69
udp port
general metric
Websites
13,500,000
websites
vulnerability
CVSS Score
10
score
general metric
Flaw
10
flaw
general metric
Entities
37
entities
general metric
Critical Vulnerabilities
42
critical vulnerabilities
data breach
Record
570
record
infrastructure
Server
10
server
general metric
Bit
64
bit
general metric
Day Vulnerability
68,820
day vulnerability
general metric
Support
26,200
support
general metric
Jul
31
jul
general metric
Bug Aug
5
bug aug
general metric
Meta Author
3
meta author
general metric
Infection Chain
1
infection chain
data breach
Byte
16
byte
general metric
Timeline Jul
28
timeline jul
general metric
Guid
95
guid
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.