The North Korean threat actor known as the Lazarus Group has been linked to the exploitation of a recently patched zero-day vulnerability in Microsoft Windows. This attack aims to deploy a new backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.
Details of the Exploit
The vulnerability in question is identified as CVE-2026-68820, which has a CVSS score of 7.0. It affects the Windows Ancillary Function Driver for WinSock (AFD.sys) and was addressed by Microsoft during its August 2026 Patch Tuesday updates. Check Point Research reported the flaw to Microsoft in late July 2026, noting that they were aware of its successful exploitation as early as June.
Attack Methodology
The Lazarus Group’s operation, termed Operation Dream Job, employs social engineering tactics to lure victims with fake job offers from reputable firms like Lockheed Martin. Victims are approached via platforms such as LinkedIn, where attackers impersonate recruiters to build trust. Once engaged, victims are tricked into opening malicious PDFs or installing a compromised PDF viewer.
The newly identified backdoor, named Troy, allows remote access to infected machines. The attack employs two primary infection methods: DLL side-loading and a trojanized PDF viewer named SecurityPDF. The DLL side-loading method involves victims downloading an encrypted archive that triggers a chain of malicious actions, while SecurityPDF monitors opened documents for specific markers to execute embedded payloads.
Infrastructure and Evasion Techniques
The Lazarus Group has utilized compromised legitimate infrastructure, including WordPress and SharePoint sites, to facilitate command-and-control operations. This tactic complicates detection efforts as it blends malicious activity with normal web traffic. Additionally, the group has been observed using a previously undocumented PHP web shell, dubbed RelayShell, to communicate between compromised servers.
Notably, the attackers have set up at least three websites impersonating Enveil to distribute the malicious PDF viewer. The domains involved include envell[.]xyz, enveil[.]online, and uxtramine[.]org. The exact methods of how these fake portals are integrated into the social engineering campaign remain unclear.
Conclusion
The ongoing activities of the Lazarus Group underscore the evolving nature of cyber threats, particularly in critical sectors. As highlighted by Sergey Shykevich from Check Point Software, the integration of legitimate infrastructure into their attacks makes detection increasingly challenging. Organizations are urged to apply patches promptly and verify software through official channels to mitigate risks.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








