High-level overview of the DLL sideloading infection chain | Image: Check Point Research
What happened at a glance
| Actor or group | Lazarus (DPRK-linked), per Check Point Research |
| Activity type | Spear-phishing, trojanized software, zero-day exploitation |
| Targets | Defense, aerospace, and aviation firms in Europe and India |
| Scale | At least 17 compromised relay servers; global reach |
| Status | Microsoft patched CVE-2026-68820 on August 11, 2026 |
| Source | Check Point Research; Microsoft Patch Tuesday |
TL;DR
Lazarus resurfaced with a fresh wave of its Operation Dream Job campaign. The group used a Windows zero-day and fake job offers to breach defense firms. Microsoft has now patched the flaw, so admins should update fast.
What happened
Check Point Research reported a new Lazarus zero-day campaign on August 11, 2026. The North Korea-linked group targeted defense, aerospace, and aviation companies. Its lure was simple and familiar. Recruiters offered dream jobs at well-known firms.
Victims received fake offers, often impersonating the privacy tech company Enveil. Then they downloaded a trojanized PDF viewer called SecurityPDF. That viewer opened attacker-crafted documents and quietly launched a new backdoor named Troy.
The attackers also abused search engine optimization. As a result, fake vendor websites ranked high in search results. Some even appeared as the top hit for relevant queries, which boosted the campaign’s credibility.
The Windows zero-day at the core
During these intrusions, the group exploited a Windows AFD.sys flaw. Check Point Research described it plainly. “During the intrusion, the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit.”
The bug is a use-after-free race condition in the WinSock driver. Therefore, a local attacker could gain SYSTEM privileges with no user interaction. FudModule then disabled endpoint security visibility on the host.
Check Point Research explained why full details stay private for now. “We will not be disclosing full technical details of the vulnerability in this article, as it was patched on the August 11 Patch Tuesday fix.” You can read the complete Check Point Research analysis of the Dream Job attack for the full chain.
Who is behind it
Check Point Research attributes the campaign to Lazarus with high confidence. Independent coverage from BleepingComputer and The Hacker News echoed that link. Microsoft credited researchers Moshe Marelus and David Driker for the report. However, Microsoft itself did not publicly attribute the exploitation.
Attribution notes
The zero-day fits a known pattern. Lazarus abused a similar AFD.sys flaw, CVE-2024-38193, back in 2024. So this new campaign continues a long trend rather than breaking new ground.
Impact and scale
The campaign reached far beyond Europe. Check Point observed targets in Brazil, France, Germany, and India. Moreover, the group hijacked a compromised French organization to spread more phishing.
For command and control, Lazarus abused hacked Roundcube and WordPress servers. They exploited CVE-2025-49113 to plant a new PHP webshell called RelayShell. Researchers counted at least 17 relay nodes, though the true figure may be higher.
What comes next and how to stay protected
Patching is the first priority. Microsoft fixed the Lazarus zero-day on its August Patch Tuesday, so apply that update now. Defense-sector teams should treat this fix as urgent.
Practical steps
Verify recruiter messages before downloading any file. Additionally, block untrusted PDF viewers and inspect archive attachments. Finally, audit Roundcube instances and rotate leaked credentials to close the C2 path.
This Lazarus zero-day campaign shows a familiar playbook with sharper tools. Careful patching and strong email hygiene remain your best defense.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.