Published Security3 min read
The August Zero-Day Microsoft Patched Was Lazarus Buying Kernel Access
Check Point says CVE-2026-68820, the actively exploited AFD.sys privilege escalation fixed on August 11, was being used in Operation Dream Job to reach SYSTEM and blind EDR, with commands relayed through hijacked...
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Check Point Research uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and aerospace professionals with convincing fake job offers; the wave was attributed to the Lazarus Group.
- The campaign wave includes a previously unknown Windows vulnerability now patched as CVE-2026-68820, a newly documented backdoor called Troy, and command infrastructure built almost entirely from legitimate servers the attackers hijacked rather than built.
- Targets were confirmed in France, Germany, Brazil, and India.
- Check Point's report states: the attackers used a previously unknown vulnerability in Windows (CVE-2026-68820) to gain full control of infected computers and evade EDR visibility; Check Point reported the issue to Microsoft, which released a fix before the research was published.
- Check Point's report states that rather than running their own servers, the attackers are hijacking legitimate but compromised websites and webmail servers to relay commands, making malicious traffic harder to distinguish from normal activity.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Check Point Research has attributed CVE-2026-68820, the actively exploited Windows zero-day Microsoft fixed on August 11 as part of Patch Tuesday, to a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and aerospace professionals with fake job offers [1][6]. The bug is a privilege escalation flaw in AFD.sys, the kernel driver behind Windows Sockets, and according to Check Point the attackers used it to take full control of infected machines and evade EDR visibility [6][4].
The disclosure timeline was short. Check Point reported the flaw to Microsoft on July 28, Microsoft confirmed it three days later, and the fix shipped two weeks after that [7], roughly fourteen days from report to patch [8]. Targets have been confirmed in France, Germany, Brazil, and India [3].
The interesting part is what the exploit was for. In the first of two parallel infection chains, victims download an encrypted archive holding a legitimately signed PDF viewer plus a malicious DLL [9][10]. The DLL renders a convincing Lockheed Martin job description while quietly loading MISTPEN, a lightweight downloader that talks to its operators over the Microsoft Graph API and OneDrive [10]. MISTPEN runs reconnaissance, fires the AFD.sys exploit to get SYSTEM, then drops ForestTiger, a documented Lazarus backdoor, and an updated FudModule 3.1 kernel rootkit that can now tamper with Windows Smart App Control to bypass software verification [11]. That is a full stack: signed-binary delivery, cloud services for C2, a kernel exploit for privileges, and a rootkit to suppress what is left of the defenders' view.
The second chain, which Check Point says shares characteristics with an ESET-documented 2025 campaign against the UAV sector, uses a trojanized viewer called SecurityPDF distributed from sites impersonating Enveil, a privacy technology company with no involvement in the campaign whose brand was borrowed because it reads as credible to defense professionals [12][15]. The viewer checks every PDF opened through it for a hidden marker, and when it finds one, decrypts an embedded payload and loads the Troy backdoor into memory [13]. Troy is a single DLL supporting 17 operator commands covering file operations, shell access, process termination, in-memory DLL injection, and configuration updates; its name comes from a PDB path Check Point also saw in earlier Lazarus samples [14].
For network defenders, the C2 design matters as much as the zero-day. Instead of standing up their own servers, the operators built the channel out of compromised Roundcube webmail installations and WordPress sites, many vulnerable to CVE-2025-49113, infected with a previously undocumented PHP webshell Check Point calls RelayShell [16][5]. RelayShell is a relay rather than a conventional backdoor, passing commands and responses through plain text files [17]. Check Point counted at least 17 unique server identifiers in the network, with operators reaching them through commercial VPNs [19]. In at least one confirmed case, an already-breached French organization was used to send phishing to new victims, borrowing that company's reputation to clear mail filters [18].
Two things to watch. First, patch state: the August 2026 Patch Tuesday update carries the CVE-2026-68820 fix, and until it is deployed, any Dream Job foothold converts to kernel access [20]. Second, whether your public-facing Roundcube or CMS estate ends up in someone else's relay tier. Check Point notes the servers in this campaign were taken through leaked credentials and a known unpatched vulnerability, not anything exotic, which means the exposure is ordinary and the consequence is being used to phish someone else's defense contractor [21]. Indicators of compromise are in Check Point's report [22].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Check Point Research uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and aerospace professionals with convincing fake job offers; the wave was attributed to the Lazarus Group.
- [2]
The campaign wave includes a previously unknown Windows vulnerability now patched as CVE-2026-68820, a newly documented backdoor called Troy, and command infrastructure built almost entirely from legitimate servers the attackers hijacked rather than built.
- [3]
Targets were confirmed in France, Germany, Brazil, and India.
- [4]
Check Point's report states: the attackers used a previously unknown vulnerability in Windows (CVE-2026-68820) to gain full control of infected computers and evade EDR visibility; Check Point reported the issue to Microsoft, which released a fix before the research was published.
- [5]
Check Point's report states that rather than running their own servers, the attackers are hijacking legitimate but compromised websites and webmail servers to relay commands, making malicious traffic harder to distinguish from normal activity.
- [6]
CVE-2026-68820 is the same actively exploited zero-day that Microsoft patched on August 11 as part of Patch Tuesday; it is a privilege escalation flaw in AFD.sys, the kernel driver underlying Windows Sockets.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityaffairs.comPierluigi PaganiniAug 13North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
Additional citations
- Check Point Research, via SecurityAffairs
- Check Point Research report
- SecurityAffairs
- SecurityAffairs, summarizing Check Point



