The North Korean threat actor known as Lazarus Group has renewed its “Operation Dream Job” campaign, now exploiting a Windows zero-day patched this week to facilitate the spread of its backdoors, Check Point reported Tuesday.Attacks begin with fraudulent job offers, supposedly from well-known companies, sent through direct messages or platforms like LinkedIn and mainly targeting the defense and aerospace sectors in Europe and India.The attacker, posing as a recruiter, instructs the victim to download a PDF to view the alleged job details, and Check Point identified two separate versions of the attack chain across the campaign. One of these attack chains exploits a use-after-free privilege escalation vulnerability in the Windows Ancillary Function Driver (AFD) for WinSock tracked as CVE-2026-68820.In this version of the attack, the victim first receives an archive containing a malicious DLL, an encrypted payload disguised as a PDF and a legitimate, digitally signed PDF viewer called SmartaPDF.exe. When the victim launches the PDF viewer, it sideloads the DLL, libmupdf.dll, which decrypts the payload and displays a decoy PDF while also executing a downloader known as MISTPEN.MISTPEN reaches attacker infrastructure via the Microsoft Graph API and OneDrive and runs reconnaissance and persistence modules before escalating privileges via CVE-2026-68820 to gain kernel access. This exploit enables the attackers to deploy a rootkit known as FudModule v3.1, which disables logging systems, suppresses security software and, in the newest version, also disrupts Smart App Control, Check Point said.Denis Calderone, CTO at Suzu Labs, noted in an email to SC Media that this is at least the third time in two years that Lazarus has exploited vulnerabilities in built-in Windows drivers to deploy FudModule, having previously exploited an appid.sys AppLocker flaw tracked as CVE-2024-21338 and another AFD.sys flaw tracked as CVE-2024-38193.“For a while, the standard playbook for getting kernel access was bring-your-own-vulnerable-driver: load a signed but buggy third-party driver, exploit it, get kernel privileges. Defenders adapted with driver allowlisting,” Calderone said. “Lazarus adapted by finding bugs in drivers that Windows ships by default. AFD.sys handles every socket operation on every Windows machine. You can’t blocklist it.”The MISTPEN version of the attack chain ultimately deploys a previously documented backdoor known as ForestTiger. However, a second version of the attack chain deploys a novel backdoor called Troy.In this alternative attack chain, victims are told to download a trojanized PDF viewer called SecurityPDF from a domain impersonating the legitimate privacy technology company Enveil. The trojanized viewer is designed to search for a hidden marker in any PDF it opens and launch an embedded payload when this marker is detected.When the attacker’s PDF, displaying a fake job description, is viewed, the attack is triggered and SecurityPDF loads the Troy backdoor directly in memory. Troy supports 17 different commands including interactive shell access, process termination, in-memory DLL injection and the ability to enumerate, upload, download, and archive and exfiltrate files.Lazarus is increasingly using compromised WordPress and Roundcube Webmail servers to serve as attacker infrastructure for its backdoors, namely ForestTiger, rather than hosting their own. The Check Point researchers noted that many of the affected Roundcube Webmail servers are vulnerable to remote code execution (RCE) flaw tracked as CVE-2025-49113. Several compromised WordPress and Roundcube instances were found to be infected with a PHP webshell dubbed RelayShell.“Check Point Research identified at least seventeen unique server identifiers associated with this relay network, and observed the operators connecting through commercial VPN services to further obscure their location,” Check Point said in a blog post.CVE-2026-68820 was reported by Check Point to Microsoft and patched as part of Microsoft’s August 2026 Patch Tuesday updates, which fixed more than 400 security flaws in total. The flaw has also been added to Known Exploited Vulnerabilities (KEV) catalog by the Cybersecurity and Infrastructure Security Agency (CISA), with federal civilian executive branch agencies ordered to patch by August 25.“This CVE carries a CVSS 7.0, rated Important. There are 42 Critical patches in the same August Patch Tuesday release. If your vulnerability management program triages by severity score, this one is going to land in the middle of the queue behind remote code execution bugs that nobody has actually exploited yet. That’s exactly backwards,” Calderone noted.
Threat Management, Threat Intelligence
DPRK’s Lazarus Group exploits Windows zero-day in backdoor campaign
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
