Actor Profile

Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group linked to the Reconnaissance General Bureau. The group is financially and strategically motivated, conducting espionage operations targeting defense and critical infrastructure sectors globally. Lazarus is known for sophisticated supply chain attacks, zero-day exploitation, and long-running social engineering campaigns. In this activity, the group leveraged CVE-2026-68820, a Windows zero-day vulnerability, to compromise defense-sector organizations as part of Operation Dream Job, a multi-year campaign using fraudulent recruitment lures to gain initial access to high-value targets.

TTPs (Tactics, Techniques, Procedures)

Lazarus employed a multi-stage attack chain incorporating zero-day exploitation, privilege escalation, and defense evasion. The group exploited CVE-2026-68820, a use-after-free vulnerability in Windows AFD.sys (Ancillary Function Driver for WinSock), to escalate privileges to SYSTEM level on Windows 11 builds 26100 and 26200. The exploit was integrated into an updated version of the FudModule kernel-mode rootkit, which disables EDR telemetry, interferes with security products, and tampers with Smart App Control. Initial access was achieved via spear-phishing with fraudulent job offers (T1566 - Phishing). The group deployed a new backdoor named Troy supporting 17 commands including reconnaissance, file operations, command execution, process injection (T1055), and exfiltration. Lazarus also compromised Roundcube webmail servers by exploiting CVE-2025-49113, an authenticated PHP object-deserialization vulnerability, after obtaining leaked credentials. A custom PHP webshell called RelayShell was deployed on at least 17 servers to maintain persistence and hide C2 communications within legitimate web infrastructure. Additional TTPs include T1068 (Exploitation for Privilege Escalation), T1014 (Rootkit), T1562.001 (Impair Defenses: Disable or Modify Tools), T1059 (Command and Scripting Interpreter), and T1041 (Exfiltration Over C2 Channel).

Targets & Patterns

Lazarus targeted defense, aerospace, and aviation organizations in Western Europe (France, Germany), India, and South America (Brazil). The campaign focused heavily on entities involved in military technologies including surveillance sensors, drones, and robotics. The targeting pattern reflects North Korean strategic intelligence priorities, seeking access to advanced military capabilities and defense industrial base secrets. Lazarus employed spear-phishing with fraudulent recruitment offers tailored to employees at target organizations, a hallmark of Operation Dream Job. In at least one instance, the group compromised an organization in France and weaponized it as infrastructure for subsequent spear-phishing attacks against additional targets, demonstrating supply chain compromise tactics. The selection of defense contractors and military technology firms aligns with state-sponsored espionage objectives to acquire sensitive technical data and intellectual property related to advanced weapons systems and surveillance capabilities.

Historical Context

This activity represents the latest evolution of Operation Dream Job, a long-standing Lazarus campaign dating back several years that uses fake recruitment lures to compromise targets. Check Point researchers noted this is not the first time Lazarus has exploited a zero-day vulnerability in Windows AFD.sys (Ancillary Function Driver for WinSock) to elevate privileges and deploy the FudModule rootkit. The group has consistently refined its toolset, with this campaign introducing updated versions of FudModule featuring Smart App Control tampering capabilities, the new Troy backdoor with expanded command functionality, and the RelayShell webshell for compromising web infrastructure. The researchers assess that Lazarus has evolved toward stealthier operations that adapt to targeted environments, including the abuse of legitimate compromised web infrastructure (Roundcube instances) to hide malicious communications and blend with normal network traffic. This progression demonstrates Lazarus' commitment to operational security improvements and tool development in response to defensive measures.

Defensive Recommendations

  • Apply Microsoft's August 2026 Patch Tuesday updates immediately to remediate CVE-2026-68820; prioritize patching Windows 11 builds 26100 and 26200 in defense-sector environments
  • Monitor for suspicious AFD.sys driver activity and unexpected privilege escalation to SYSTEM level, particularly from user-mode applications triggering race conditions
  • Deploy Check Point's published YARA rule to detect RelayShell webshell and scan externally facing Roundcube installations for compromise indicators; patch CVE-2025-49113 in all Roundcube instances
  • Implement behavioral detection for FudModule rootkit activity including EDR telemetry suppression (T1562.001), Smart App Control tampering, and kernel-mode driver loading from unexpected paths
  • Enhance email security controls to detect Operation Dream Job social engineering patterns: unsolicited recruitment offers, especially targeting defense/aerospace employees, with suspicious attachments or links (T1566)
  • Monitor for Troy backdoor behaviors including in-memory DLL injection (T1055), hidden command execution, and file exfiltration via archive creation followed by upload activity
  • Audit credential exposure and implement credential hygiene programs to prevent initial Roundcube compromise via leaked credentials; enforce MFA on all webmail and external-facing services

---

# Geopolitical Context

Geopolitical Context

The exploitation of CVE-2026-68820, a Windows zero-day vulnerability, by the North Korea-linked Lazarus group represents a continuation of Pyongyang's strategic intelligence collection priorities targeting defense industrial base entities. Operation Dream Job—a long-standing campaign using fraudulent recruitment lures—has evolved to incorporate zero-day exploitation and advanced privilege escalation techniques, reflecting sustained investment in cyber espionage capabilities. The targeting of defense, aerospace, and aviation organizations in Europe, India, and South America aligns with North Korea's documented interest in acquiring sensitive military and dual-use technologies to support its weapons programs amid international sanctions. The compromise of a French organization for use in subsequent spear-phishing operations demonstrates operational sophistication and willingness to leverage third-party infrastructure for access and persistence.

State Actor Alignment

Lazarus is widely attributed to North Korea's Reconnaissance General Bureau and operates under the strategic direction of the Democratic People's Republic of Korea (DPRK). The group's activities are consistent with state priorities including sanctions evasion, technology acquisition, and revenue generation. North Korea remains subject to comprehensive United Nations, U.S., and allied sanctions targeting its weapons of mass destruction programs and cyber operations. The targeting of defense contractors and exploitation of zero-day vulnerabilities in widely deployed operating systems underscores the DPRK's asymmetric cyber capabilities as a tool of statecraft. Microsoft's rapid patching and public attribution, alongside private-sector threat intelligence sharing, reflect coordinated efforts to impose costs on North Korean cyber operations through exposure and remediation.

Business Impacty pro region

The campaign's geographic scope—spanning Western Europe (France, Germany), India, and South America (Brazil)—indicates Lazarus is pursuing a diversified target set beyond traditional U.S. and allied defense sectors. European defense entities face heightened risk as the continent increases military spending and industrial cooperation in response to regional security challenges. The compromise of a French organization for onward operations may complicate attribution and response efforts, particularly if victim notification and information-sharing mechanisms are delayed. India's growing defense manufacturing base and technology partnerships make it an attractive target for North Korean intelligence collection. The extension into South America suggests interest in emerging defense markets or supply chain vulnerabilities. The abuse of legitimate web infrastructure (compromised Roundcube instances) complicates network defense and may hinder detection in environments with limited visibility into third-party services.

Forecast

If North Korean cyber operations continue to prioritize defense sector espionage with zero-day capabilities, targeted organizations are likely to face sustained intrusion attempts leveraging social engineering and unpatched vulnerabilities. Should Lazarus maintain access to zero-day exploits—whether developed indigenously or acquired through third parties—the group may expand targeting to additional critical infrastructure sectors aligned with DPRK strategic priorities. If international sanctions enforcement remains robust, Pyongyang is likely to rely increasingly on cyber espionage to circumvent technology transfer restrictions and support military modernization. Should public-private threat intelligence sharing and rapid patching cycles continue, the operational lifespan of Lazarus zero-day exploits may decrease, potentially forcing adaptation toward less sophisticated but higher-volume intrusion methods. If compromised third-party infrastructure remains a viable operational vector, defenders may need to enhance monitoring of externally hosted services and supply chain partners to detect lateral movement and command-and-control activity.