Skip to content
Lazarus Group Exploited Windows Zero

Lazarus Group Exploited Windows Zero

Finance.Biggo August 12, 2026

The North Korean state- hacking collective Lazarus Group exploited a previously unknown vulnerability in Microsoft Windows to gain SYSTEM-level access on targeted machines and deploy a newly identified backdoor, according to research published Tuesday by Check Point Research.

The flaw, tracked as CVE-2026-68820 with a CVSS score of 7.0, resides in the Windows Ancillary Function Driver for WinSock, commonly known as AFD.sys. Microsoft patched the privilege escalation vulnerability as part of its August 2026 Patch Tuesday release, which addressed a total of 421 bugs across its product portfolio. Check Point researchers Moshe Marelus and David Driker were credited with discovering and reporting the issue.

Check Point's threat intelligence director Sergey Shykevich said his analysts first observed Lazarus Group actively exploiting the vulnerability in early June, roughly two months before the fix became available. "We are familiar with one successful implementation of the CVE, but we assume it was used widely in the campaign," Shykevich told The Register.

The exploitation forms part of Operation Dream Job, a cyber espionage campaign that has been running since 2020. The operation uses fake recruiter personas on and other platforms to lure professionals with enticing job offers at defense and technology companies, then directs them to download malicious files. The latest wave targeted defense and aerospace organizations across France, Germany, Brazil, and India, with lures impersonating Lockheed Martin and the privacy technology firm Enveil.

Check Point identified two parallel infection chains in the recent activity. In the first, victims receive an encrypted archive that triggers a DLL side-loading sequence. A malicious library named libmupdf.dll displays a fake job description while silently downloading and executing MISTPEN, a lightweight downloader that communicates with attacker infrastructure through Microsoft Graph API and OneDrive. MISTPEN retrieves reconnaissance and persistence modules, triggers the AFD.sys exploit, and ultimately deploys ForestTiger, a remote access tool also known as ScoringMathTea.

The second chain involves a trojanized PDF viewer called SecurityPDF, distributed through at least three websites impersonating Enveil. Once installed, SecurityPDF monitors for PDF documents containing a specific marker string: "This document is encrypted with sumatrapdf reader!!!!!!!!!!!!" When such a file is opened, the application decrypts and executes an embedded payload that loads a new backdoor named Troy directly into memory. Troy supports 17 operator commands, including file enumeration, upload and download capabilities, archive and exfiltration functions, interactive shell access, process termination, in-memory DLL injection, and configuration updates.

The attackers registered at least three domains to distribute the malicious PDF viewer: envell[.]xyz, enveil[.]online, and uxtramine[.]org. Some of these fake sites reportedly ranked at the top of results, lending them an air of legitimacy that made the social engineering more convincing.

MISTPEN loads at least four distinct modules after establishing its foothold. GetInfoPlugin profiles the host and exfiltrates collected information as a single wide-character string. PvPlugin gathers reconnaissance data and details running processes. OneScreenCapture takes screenshots of all connected monitors and transmits them as JPEG images. The fourth module, an LPE loader, generates key material using the ML-KEM post-quantum key encapsulation algorithm and decrypts FudModule during the handshake process.

FudModule, a kernel-mode rootkit Lazarus has used since at least 2022, received an update in this campaign. Check Point identified the new version as FudModule 3.1, which adds the ability to tamper with Smart App Control, a Windows feature designed to verify whether programs are safe to run. The rootkit exploits the AFD.sys vulnerability to obtain SYSTEM privileges and injects another instance of MISTPEN into a SYSTEM process, allowing it to operate with elevated privileges while evading security tools.

"Within the SYSTEM-level msiexec.exe child process, its remote stub sets VerifiedAndReputablePolicyState to zero and invokes NtSetSystemInformation class 0xA4 with option 0x10000000, triggering an in-place reload of the code integrity policy," Check Point researchers wrote in their technical analysis.

Rather than building dedicated infrastructure, the attackers hijacked legitimate but compromised WordPress and SharePoint websites, along with vulnerable Roundcube webmail servers, to serve as command-and-control infrastructure for ForestTiger. Many of the Roundcube servers were found to be vulnerable to CVE-2025-49113, which the group leveraged to install RelayShell, a previously undocumented PHP web shell that exchanges commands and responses through text files. In at least one case, an already compromised French organization was used to send phishing messages to new victims, helping bypass reputation-based email filters.

Shykevich emphasized that the campaign's danger extends beyond the zero-day itself. "What makes this campaign so dangerous is not only the zero-day vulnerability, but also how Lazarus wove legitimate, trusted infrastructure into every stage of the attack," he said. "They hid in plain sight, behind top-ranked results, real vendor branding, and the reputation of organizations they had already compromised."

The August Patch Tuesday release addressed 421 vulnerabilities, down from roughly 200 more in the prior month. Microsoft flagged only two as notable: CVE-2026-68820 and CVE-2026-62832, an elevation-of-privilege flaw that Microsoft says is "more likely" to be exploited. Trend Micro's Zero Day Initiative highlighted five additional bugs warranting attention, including CVE-2026-62893, a critical remote code execution flaw in Windows Deployment Services TFTP Server, and CVE-2026-62911, an Exchange Server authentication bypass demonstrated at the Pwn2Own contest in Berlin.

The latest findings indicate that Lazarus Group continues to refine its malware arsenal and operational tradecraft while maintaining the core structure of Operation Dream Job. The group, active since at least 2009, is best known for the 2014 Sony Pictures Entertainment hack and the 2017 WannaCry ransomware outbreak, though its activities also span cryptocurrency theft, extortion, and IT worker scams.

Shykevich offered a sobering assessment for defenders. "When the website, the download and the recruiter all appear authentic, the old advice to spot the phishing link is no longer easily applicable," he said. "Staying safe now means assuming that trust itself can be counterfeited: patch the moment updates land, verify software through official channels rather than rankings, and extend zero-trust thinking to the legitimate-looking sites and partners we interact with every day."

Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.