mimile
Back to feed
This event is part of a larger story
Франция, Казахстан, Польша: кибератаки раскрыли данные сотен тысяч
Read briefing

Lazarus Group exploits Windows zero-day CVE-2026-68820 in global defense attacks

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Lazarus Group exploits Windows zero-day CVE-2026-68820 in global defense attacks

The North Korean Lazarus Group exploited a zero-day in the Windows afd.sys driver to compromise defense and aerospace organizations across Europe and India. Microsoft patched the vulnerability on August 11 as part of its Patch Tuesday updates, and CISA added it to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch within two weeks. Linked to the long-running Operation Dream Job, the attacks continue to leverage new malware like Troy and RelayShell, despite the patch.

The Zero-Day and Response

The vulnerability, tracked as CVE-2026-68820, is a use-after-free flaw in Windows’ Ancillary Function Driver for WinSock (afd.sys) that allows privilege escalation to System level. Check Point reported that the North Korean Lazarus Group has been exploiting it since early 2026 in targeted attacks. Microsoft released a fix in its August 11 Patch Tuesday updates, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) immediately added the bug to its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies are required to apply the patch by August 25, though the threat group is known to quickly adapt.

Infection Chains and Malware

The attackers, posing as recruiters on professional platforms, lure victims into downloading malicious archives. One chain uses a ZIP file with a PDF viewer, a malicious DLL, and an encrypted payload; sideloading executes the Mistpen downloader before exploiting the zero-day to deploy the ForestTiger backdoor. A second chain delivers a trojanized PDF viewer called SecurityPDF, which scans for a hidden marker to execute the new Troy backdoor directly in memory. Troy supports 17 commands for system control and data exfiltration. Command-and-control infrastructure relies on compromised Roundcube and CMS servers, many infected with the previously undocumented RelayShell webshell, which relays commands via text files. The campaign has hit aerospace and defense organizations in France, Germany, Brazil, and India.

What's Next

CISA’s patch deadline for U.S. federal agencies falls on August 25, but it may take longer for all affected organizations to protect their systems. Check Point warns that the Lazarus Group’s Operation Dream Job continues to evolve, raising the question of whether the group has other zero-day exploits in reserve.

1 source

Lazarus Group exploits Windows zero-day CVE-2026-68820 in global defense attacks