In a chilling display of advanced cyber warfare, the notorious North Korean threat actor, Lazarus Group, has been caught exploiting a previously unknown zero-day vulnerability in Microsoft Windows. This sophisticated attack, part of their long-running “Operation Dream Job” campaign, targeted critical defense and aerospace sectors across France, Germany, Brazil, and India, deploying a novel backdoor to achieve complete system compromise.
Operation Dream Job: A Web of Deceit
For years, the Pyongyang-backed Lazarus Group has perfected the art of cyber espionage through “Operation Dream Job.” This elaborate social engineering campaign preys on professionals worldwide, luring them with highly convincing, yet fake, job offers from prestigious firms like Lockheed Martin and Enveil. Posing as legitimate recruiters on platforms such as LinkedIn, the attackers meticulously build trust, ultimately tricking victims into installing malware or divulging sensitive information.
Unmasking the Zero-Day Exploit: CVE-2026-68820
The latest wave of attacks leveraged a critical privilege escalation flaw, identified as CVE-2026-68820 (CVSS score: 7.0), within the Windows Ancillary Function Driver for WinSock (“AFD.sys”). This zero-day vulnerability, only recently patched by Microsoft in its August 2026 Patch Tuesday updates, allowed the Lazarus Group to elevate their privileges to SYSTEM level, granting them unparalleled control over compromised machines.
Dual-Pronged Infection: DLL Side-Loading and Trojanized PDFs
Check Point Research‘s findings reveal two parallel and equally insidious infection sequences employed by the group:
The DLL Side-Loading Chain
In this method, victims are instructed to download an encrypted archive. This archive then triggers a complex DLL side-loading chain. A malicious DLL, “libmupdf.dll,” is used to display a seemingly innocuous job description, while in the background, it stealthily downloads and executes a lightweight downloader known as MISTPEN. MISTPEN then leverages the Microsoft Graph API and OneDrive to communicate with the attackers’ infrastructure, retrieving reconnaissance and persistence modules. Crucially, it triggers the “AFD.sys” driver exploit before deploying ForestTiger (also known as ScoringMathTea), a backdoor granting remote access to the host.
The Trojanized “SecurityPDF” Viewer
Alternatively, victims are directed to download a malicious “SecurityPDF” viewer from websites impersonating legitimate entities like Enveil. Once installed, this trojanized application monitors for any PDF document opened through it that contains a specific marker. Upon detection, it decrypts and launches an embedded payload, directly injecting a sophisticated backdoor named Troy into memory. This DLL implant boasts 17 operator commands, enabling extensive malicious activities including file enumeration, upload/download, archiving, exfiltration, interactive shell access, process termination, and in-memory DLL injection.
Advanced Evasion and Persistence
The Lazarus Group’s tactics extend beyond initial compromise. MISTPEN, for instance, loads several modules to gather intelligence and maintain persistence:
- GetInfoPlugin: Profiles the host and exfiltrates collected information.
- PvPlugin: Gathers host reconnaissance data and details about running processes.
- OneScreenCapture: Takes screenshots of the desktop and transmits them as JPEG images.
- LPE Loader: Collects host information, generates new key material using the ML-KEM post-quantum key encapsulation algorithm, and decrypts and runs FudModule.
The attack chain also incorporates an updated version of a kernel-mode rootkit, FudModule 3.1, which the Lazarus Group has utilized since 2022. This rootkit is designed to conceal malicious tools from security software. FudModule 3.1 specifically exploits the “AFD.sys” vulnerability to obtain SYSTEM privileges and injects MISTPEN into a SYSTEM process, allowing it to operate with elevated access and evade detection. A significant enhancement in FudModule 3.1 is its ability to tamper with Windows’ Smart App Control, a feature designed to verify program safety. By manipulating the
VerifiedAndReputablePolicyState
and invoking specific system information classes, the rootkit triggers an in-place reload of the code integrity policy, effectively neutralizing this crucial security control.
Impersonation and the Ongoing Threat
The attackers went to great lengths, creating at least three fake websites impersonating Enveil to distribute their malicious “SecurityPDF” viewer. While the exact integration of these fake portals into the broader social engineering campaign remains under investigation, it underscores the meticulous planning and resources behind Lazarus Group’s operations.
This latest campaign highlights the persistent and evolving threat posed by state-sponsored actors like the Lazarus Group. Their willingness to invest in zero-day exploits, coupled with sophisticated social engineering and advanced evasion techniques, demands heightened vigilance from organizations, especially those in critical defense and aerospace sectors.
For more details, visit our website.
Source: Link








Leave a comment