The North Korean Lazarus Group has been caught exploiting a newly patched Windows zero-day vulnerability as part of its long-running Operation Dream Job campaign. The flaw, tracked as CVE-2026-68820, targets the Windows Ancillary Function Driver for WinSock (AFD.sys) and allows attackers to escalate privileges to SYSTEM. Defense and aerospace companies across France, Germany, Brazil, and India have been targeted with fake job offers on LinkedIn that deliver a brand-new backdoor called Troy.
What Happened: Lazarus Exploits Windows Zero-Day to Deploy Troy Backdoor
Check Point Research attributed the activity to Lazarus Group, a prolific North Korean advanced persistent threat (APT). The campaign uses fake recruiter personas on LinkedIn pretending to represent firms like Lockheed Martin and Enveil. Victims are lured into opening malicious PDFs or installing a trojanized PDF viewer named SecurityPDF.
The attack exploits CVE-2026-68820 (CVSS score: 7.0), a privilege escalation flaw in AFD.sys. Check Point reported the vulnerability to Microsoft in late July 2026. However, the researchers noted they are familiar with successful exploitation dating back to early June 2026. Microsoft patched the flaw during its August 2026 Patch Tuesday.
CISA added CVE-2026-68820 to its Known Exploited Vulnerabilities Catalog on August 11, 2026. The due date for federal agencies to remediate is August 25, 2026. Furthermore, the vulnerability is part of BOD 26-04, which prioritizes security updates based on risk.
Technical Details of the Attack Chain
The Lazarus Group used two parallel infection sequences. Both paths ultimately lead to SYSTEM-level access and deployment of the Troy backdoor. Below are the two observed attack chains.
Infection Chain One: DLL Side-Loading
Victims download an encrypted archive that triggers a DLL side-loading chain. The malicious DLL (libmupdf.dll) displays a fake job description while stealthily downloading MISTPEN in memory. MISTPEN communicates via Microsoft Graph API and OneDrive to retrieve reconnaissance modules. Then it triggers the AFD.sys exploit and deploys ForestTiger for remote access.
Infection Chain Two: Trojanized SecurityPDF Viewer
Victims are urged to download SecurityPDF from websites impersonating Enveil. Once installed, the application monitors opened PDFs for a special marker. When the marker is present, it decrypts and loads Troy directly into memory. Troy supports 17 operator commands including file enumeration, upload, download, archive, exfiltration, interactive shell, process termination, in-memory DLL injection, and configuration updates.
Business and Operational Impact
The targeting of defense and aerospace sectors makes this campaign especially concerning. Below are the key impacts:
- Defense sector compromise: Companies in France, Germany, Brazil, and India were targeted, risking theft of sensitive military and aerospace designs.
- Complete host takeover: Successful exploitation grants SYSTEM privileges, allowing attackers to disable security tools and maintain long-term persistence.
- Data exfiltration: MISTPEN modules profile hosts, capture screenshots, and steal credentials through ForestTiger C2 channels.
- Reputational damage: Legitimate compromised organizations were used to send phishing to new victims, bypassing reputation filters.
- Smart App Control bypass: FudModule 3.1 tampers with Windows code integrity policies, weakening endpoint protection.
Mitigation and Recommendations
Organizations should take immediate steps to reduce exposure and detect potential compromise. The following actions are recommended.
Immediate Actions for Defenders
- Patch CVE-2026-68820 via Microsoft August 2026 Patch Tuesday updates immediately.
- Block the known malicious domains envell[.]xyz, enveil[.]online, and uxtramine[.]org at the perimeter.
- Hunt for indicators of MISTPEN, ForestTiger, and Troy in endpoint telemetry.
- Audit Microsoft Graph API and OneDrive connections for unauthorized tokens.
- Warn employees about fake recruiter outreach on LinkedIn and unsolicited PDF viewers.
Detection Guidance
- Monitor for anomalous child processes spawned by msiexec.exe with elevated integrity.
- Look for attempts to modify VerifiedAndReputablePolicyState registry values.
- Inspect web logs for unusual PHP web shell activity on Roundcube servers.
Bottom line: Patch CVE-2026-68820 immediately, block the three known malicious domains, and train staff to verify recruiter identities before downloading any software. Lazarus Group hid behind legitimate branding and compromised infrastructure, so trust itself must be verified rather than assumed.
Incident Summary
| CVE ID / Incident: | CVE-2026-68820 |
| Affected Systems: | Microsoft Windows (AFD.sys driver) |
| Disclosure Date: | August 2026 (Microsoft Patch Tuesday); CISA KEV added August 11, 2026 |
| Patch Status: | Patch available via Microsoft August 2026 updates |
| Threat Actor: | Lazarus Group (North Korea / APT38) |
| Campaign: | Operation Dream Job |
| Target Sectors: | Defense and aerospace in France, Germany, Brazil, India |
References
- Check Point Research, “State-Sponsored Hackers Use Fake Job Offers to Deliver New Zero-Day Exploit,” August 2026. https://blog.checkpoint.com/research/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit/
- The Hacker News, “Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor,” August 17, 2026. https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html
- Microsoft Security Response Center, CVE-2026-68820 Update Guide, August 2026. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820
- CISA Known Exploited Vulnerabilities Catalog, CVE-2026-68820 entry, accessed August 17, 2026. https://www.cisa.gov/known-exploited-vulnerabilities-catalog