North Korean hackers linked to Lazarus are exploiting the Windows zero-day CVE-2026-68820 in the Operation Dream Job campaign to gain SYSTEM privileges on targeted systems. The attacks have focused on defense, aerospace, and aviation organizations, while also using the FudModule rootkit, the Troy backdoor, and the RelayShell web shell to expand access and evade defenses. #CVE-2026-68820 #Lazarus #OperationDreamJob #FudModule #Troy #RelayShell #Roundcube
Keypoints
- Lazarus exploited CVE-2026-68820 in Windows AFD.sys to elevate privileges.
- The Operation Dream Job campaign targeted defense, aerospace, and aviation groups.
- The exploit was embedded in a new FudModule rootkit variant for Windows 11.
- The attackers deployed the Troy backdoor and the RelayShell web shell.
- Compromised Roundcube servers and leaked credentials were used to support intrusion activity.