Particle.news

Lazarus Exploits Windows Zero‑Day in New 'Operation Dream Job' Wave

The flaw lets attackers gain SYSTEM privileges to install a stealthy kernel rootkit, a risk that has prompted urgent patches and IOC guidance.

Overview

  • Security firm Check Point attributes a fresh wave of Operation Dream Job intrusions to the North Korea‑linked Lazarus Group that used fake recruiter lures to get initial code running on victims.
  • Microsoft released a Patch Tuesday fix for CVE-2026-68820 on Tuesday, Aug. 11, and CISA added the bug to its Known Exploited Vulnerabilities list, prompting agencies and defenders to patch fast.
  • Researchers documented two parallel delivery chains: a DLL sideloading path that runs the in-memory MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that launches the new Troy backdoor.
  • After local code execution the attackers used CVE-2026-68820, a use‑after‑free in the Windows AFD.sys driver, to escalate to SYSTEM and deploy FudModule v3.1, a kernel rootkit that disables telemetry and tampers with Smart App Control.
  • Operators hid command traffic on compromised Roundcube and CMS servers using a new PHP webshell called RelayShell and abused top-ranked spoofed vendor sites, so defenders are urged to apply the patch, hunt IOCs, verify downloads through vendor channels, and treat unsolicited recruiter requests as high risk.