Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

sofx+1sofx+1sofx+1North Korea's Lazarus Group exploited a previously unknown Windows vulnerability to seize control of computers at defense, aerospace, and aviation companies across multiple countries, wrapping the attack in quantum-resistant encryption to conceal the exploit during delivery, researchers disclosed this week.
Microsoft patched the flaw, tracked as CVE-2026-68820, on August 11 as part of its monthly security update, and the Cybersecurity and Infrastructure Security Agency ordered federal civilian agencies to apply the fix by August 25. Check Point Research, which discovered the vulnerability and reported it to Microsoft on July 28, said Lazarus had been running the exploit since at least early July, with a recovered rootkit sample carrying a build date of July 7.sofx+1
The intrusions are the latest wave of Operation Dream Job, a Lazarus campaign active since 2020 in which operators pose as recruiters and approach engineers with fraudulent job offers. In this round, attackers impersonated recruiters for Lockheed Martin and privacy-technology firm Enveil, contacting targets on LinkedIn and messaging apps before delivering malicious files disguised as recruitment material. Check Point said Enveil was neither targeted nor compromised.etvbharat+2
The vulnerability itself is a use-after-free race condition in AFD.sys, the Windows driver handling network socket connections. It allows an attacker with an existing foothold to escalate to SYSTEM privileges without user interaction. Check Point confirmed the exploit on a fully updated Windows 11 system.bleepingcomputer+2
What distinguishes this wave is the delivery mechanism. Before pulling down the privilege-escalation exploit, the malware negotiated its command channel using Kyber (ML-KEM), the key encapsulation scheme standardized by the U.S. National Institute of Standards and Technology in 2024 to resist future quantum-computer attacks. Layering that over conventional encryption made the exploit delivery harder for defenders to inspect.sofx
Once installed, the payload was FudModule, a Lazarus kernel rootkit that disables 94 Event Tracing for Windows monitoring channels and tampers with Smart App Control. The group ran its infrastructure almost entirely on machines it did not own, using hijacked Roundcube webmail servers and compromised online stores to relay traffic. Check Point identified at least 17 such servers.bleepingcomputer+1
Targets were concentrated in France, Germany, Brazil, and India, with at least one compromised French organization used to launch spear-phishing attacks on additional victims.etvbharat+1
Sergey Shykevich, threat intelligence director at Check Point, said the danger lay in how the group folded trusted infrastructure into every stage. "They hid in plain sight, behind top-ranked search results, real vendor branding, and the reputation of organizations they had already compromised," he said.sofx