INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

North Korean Lazarus Group Exploits Windows Zero-Day

| 2026-08-13 07:05 CRITICAL HIGH
Executive Summary AI-generated
The North Korean Lazarus Group has launched a new wave of Operation Dream Job, exploiting a previously unknown Windows vulnerability to gain full control of infected computers and evade EDR visibility. The group's tactics include hijacking legitimate websites and webmail servers, deploying backdoors such as ForestTiger and FudModule 3.1, and using compromised Roundcube infrastructure to establish command and control (C2) connections with its operatives. This iteration is more dangerous than previous versions due to the newly documented Troy backdoor and the use of hijacked legitimate servers, making it harder for endpoint security solutions to detect and block the malicious traffic.
Technical Mitigations AI-generated
* Use up-to-date and patched operating systems, software, and firmware to minimize the risk of exploitation. * Implement robust security controls, such as firewalls, intrusion detection systems, and antivirus software, to detect and block malicious traffic. * Conduct regular vulnerability assessments and penetration testing to identify potential weaknesses and address them before they can be exploited. * Use secure coding practices, such as input validation and sanitization, to prevent the introduction of vulnerabilities in code. * Implement a least-privilege access model for all users and systems, with strict controls on user privileges and permissions.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Dream JobOperation Dream JobOperation DreamJobOperation DreamJob Lazarus GroupLazarus Group CVE-2025-60719CVE-2025-60719 CVE-2026-59124CVE-2026-59124 CVE-2026-62878CVE-2026-62878 CVE-2026-62832CVE-2026-62832 CVE-2026-62893CVE-2026-62893 CVE-2026-68820CVE-2026-68820 CVE-2026-72971CVE-2026-72971 CVE-2025-49113CVE-2025-49113 CVE-2026-55040CVE-2026-55040 CVE-2026-63520CVE-2026-63520 CVE-2026-62911CVE-2026-62911 CVE-2026-62815CVE-2026-62815 CVE-2024-38193CVE-2024-38193
Target & Sectors
DPRK DPRK FIVE_EYES FIVE_EYES LATAM LATAM DACH DACH aerospaceaerospace technologytechnology governmentgovernment aviationaviation defensedefense mediamedia
Incident Timeline
‎around 2021
Threat actors used the Lazarus Group's FudModule to exploit a Windows Zero-Day vulnerability and gain system access.
tactic Privilege Escalation
‎2025/08/11
Threat actors used Lazarus Group's Windows Zero-Day exploit to gain system access through a backdoor installed by the Troy malware.
organisation ESET
organisation E:\Work\Troy\안정화\
organisation Command and Control
‎2025/08/12
Threat actors exploited a recently discovered Windows Zero-Day vulnerability to gain system access.
‎November 2025
Threat actors exploited a previously unknown Windows Zero-Day vulnerability, CVE-2025-60719.
vulnerability CVE-2025-60719
‎May 18
The Lazarus Group exploited a Windows Zero-Day vulnerability to gain system access through an authentication bypass and code execution on May 18.
‎July 7, 2026
Threat actors exploited a recently discovered Windows Zero-Day (CVE-2026-68820) in the Afd4Eop12_x64.dll file.
vulnerability CVE-2026-68820
observable Afd4Eop12_x64.dll
organisation UTC
‎2026/07/13
Threat actors used a newly discovered Windows Zero-Day exploit to gain system access.
organisation LegacyHive
organisation Nightmare
‎July 2026
Threat actors used a newly discovered Windows Zero-Day to infect systems through a Trojanized PDF viewer.
campaign Operation Dream Job
general_metric 2.0 reference
‎at least early July 2026
Threat actors used a previously undisclosed Windows Zero-Day vulnerability to target an unpatched version of the operating system.
infrastructure Windows
general_metric 11 Windows
organisation Operation ‘Dream Job
‎July 28
Check Point Research discovered and reported the vulnerability to Microsoft on July 28, which was then confirmed by Microsoft three days later.
organisation Check Point Research
organisation Microsoft
‎Jul 28, 2026
Threat actors exploited a recently discovered Windows zero-day vulnerability to gain system access.
‎Jul 31, 2026
Threat actors exploited a previously unknown Windows Zero-Day vulnerability to gain unauthorized access to targeted systems.
‎Aug 5, 2026
Threat actors exploited a recently discovered Windows Zero-Day vulnerability to gain system access.
‎August 11
Threat actors used a previously unknown Windows Zero-Day vulnerability, CVE-2026-68820, to gain system access by hijacking legitimate websites and webmail servers.
infrastructure Windows
tactic Privilege Escalation
vulnerability CVE-2026-68820
organisation Check Point Research
organisation Microsoft
‎August 11, 2026
Threat actors exploited a recently discovered Windows Zero-Day vulnerability, CVE-2026-68820.
vulnerability CVE-2026-68820
‎Aug 11, 2026
Threat actors exploited a recently discovered Windows Zero-Day vulnerability to gain unauthorized access to targeted systems.
‎Aug 12, 2026
Threat actors exploited a recently discovered Windows zero-day vulnerability to gain unauthorized access to targeted systems.
‎August 2026
The Lazarus Group exploited CVE-2026-68820, a privilege escalation flaw in the Windows Ancillary Function Driver for WinSock.
vulnerability CVE-2026-68820
infrastructure Windows
tactic Privilege Escalation
organisation Microsoft
organisation Windows Ancillary Function
infrastructure 7.0
organisation Patch Tuesday
general_metric 7.0 attacks
tactic Remote Code Execution
organisation DNS
organisation SharePoint
organisation Windows, Office
tactic T1584.004 - Server
organisation Teams
organisation Microsoft Patch
‎early 2026
Threat actors used a recently discovered Windows zero-day to gain system access.
campaign Operation Dream Job
‎2026/08/13
Lazarus Group exploited a newly patched Windows Zero-Day vulnerability to gain system access and deploy a backdoor.
infrastructure Windows
threat_actor Lazarus Group
organisation Vulnerability / Cyber Espionage
organisation Microsoft Windows
organisation ESET
organisation Lockheed
organisation Check Point Research
organisation Infection Chain The
infrastructure Roundcube
organisation North Korean
organisation Automox
organisation Reconnaissance General Bureau
organisation FudModule
organisation CVE-2026
organisation Enveil
organisation LinkedIn
organisation PDF
organisation YARA
organisation SecurityPDF Website & Troy
infrastructure 3.1
organisation FudModule 3.1
organisation Troy
organisation EDR
organisation CVE-2026-68820
organisation Check Point
organisation ETW
organisation Windows Ancillary Function
organisation FudModule 3.1
organisation Winsock
organisation Windows Deployment Services
organisation TFTP
organisation WDS
organisation PXE
organisation Windows User Profile Service
organisation the Container Isolation FS Filter
organisation the User Profile Service
organisation the Windows Ancillary Function
organisation CVE-2026-62832
organisation the Windows User Profile Service
organisation Windows Container Isolation FS
organisation Microsoft Patches
organisation Microsoft
organisation Vulnerability / Windows Security
organisation CVSS
organisation Put CVE-2026-68820
organisation LPE
organisation PvPlugin
organisation the Windows Ancillary Function Driver
organisation ML-KEM
infrastructure 7.0
organisation PHP
organisation RelayShell
organisation DLL
organisation Microsoft Graph API
organisation OneDrive
organisation ForestTiger
organisation ScoringMathTea
organisation SEO
organisation CVE-2025-49113
organisation WordPress
organisation Command
organisation PrestaShop
organisation CVE-2025
organisation PHP Object Deserialization
organisation CMS
organisation SharePoint
organisation UAV
organisation PDB
organisation SecurityAffairs
infrastructure 17 unique server identifiers
organisation Disney
organisation Google
organisation Oracle
organisation Operation DreamJob
organisation National Cyber Security Centre
organisation Lazarus Used Post-Quantum Key Exchange
organisation Kyber/ML-KEM
organisation NIST
organisation GOST-CBC
organisation AES
organisation Mandiant
organisation Smart App Control
organisation Delivery
organisation JPEG
organisation The Blue Report 2026
organisation Backdoor Deployment:
organisation ForestTiger’s C2
infrastructure 2.0
organisation DNS
organisation HPC
organisation Important
organisation CVE-2026-59124
organisation HPC Pack
organisation Exchange
organisation Critical
infrastructure 9.1
organisation Microsoft Fixes
organisation RCE
data_breach 570 record
organisation ZDI
infrastructure 9.8 server
organisation Functionality
organisation Microsoft Defender
organisation PPL
organisation AhnLab
organisation DLL Sideloading
organisation PE DLL
organisation the Process PID
organisation PPID
organisation RPC
organisation MISTPEN’s
data_breach 16 byte
organisation Key Exchange
organisation the Microsoft Security Response Center
organisation MSRC
organisation WFP
organisation Kaspersky
organisation SuspendDefender
organisation Troy Backdoor The
organisation Lazarus’
organisation RWX
organisation Compress-Archive
organisation Terminates
organisation WMI
organisation PID
organisation WebShell
organisation Command Type Description Session
organisation Check & cleanup
organisation File-Based Communication Channel
‎August 25
Threat actors exploited a recently discovered Windows zero-day vulnerability to gain system access.
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎3.1
Software Version
Metrics
infrastructure
‎Roundcube
Affected Product
Metrics
infrastructure
17
Unique Server Identifiers
Metrics
infrastructure
‎7.0
Software Version
Metrics
infrastructure
‎2.0
Software Version
Metrics
data_breach
570
Record
Metrics
infrastructure
‎9.1
Software Version
Metrics
infrastructure
10
Server
Metrics
data_breach
16
Byte