Full research report
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Executive assessment
The evidence supports a two-stage risk: social engineering or trojanised software first establishes local execution, and CVE-2026-68820 then raises that execution to SYSTEM. CISA independently confirms in-the-wild exploitation, while Microsoft and NVD establish that the flaw is a local AFD.sys use-after-free affecting numerous Windows client and server releases. Reporting attributes the activity to Lazarus and says elevated access enabled FudModule 3.1, MISTPEN, ForestTiger and Troy while compromised legitimate services obscured command-and-control traffic. CVE-2025-49113 is related through reportedly hijacked Roundcube infrastructure, not as an alternative Windows exploitation path. The attribution and detailed malware analysis are credible but not fully independently verified because the original Check Point publication was inaccessible.
What happened
During a wave of Operation Dream Job activity investigated in 2026, attackers attributed to Lazarus used fraudulent recruitment material and trojanised PDF software to obtain initial execution on Windows systems. They then exploited CVE-2026-68820, a Windows Ancillary Function Driver for WinSock use-after-free vulnerability, to elevate locally to SYSTEM and deploy FudModule and additional backdoors. Microsoft patched the vulnerability on 11 August 2026, and CISA added it to the Known Exploited Vulnerabilities catalogue the same day.
Affected scope
Microsoft records affect supported Windows 10 and Windows 11 releases and Windows Server 2012 through 2025, with exact corrected builds varying by release. Reported campaign targets include defence, aerospace and aviation organisations in France, Germany, Brazil and India. Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 is separately affected by CVE-2025-49113; vulnerable servers were reportedly compromised for RelayShell and campaign infrastructure.
Technical assessment
CVE-2026-68820 is a high-complexity local use-after-free weakness in AFD.sys requiring prior low-privileged authorised access; it is an elevation mechanism rather than a remote initial-access flaw. In the reported intrusions, social engineering and malicious software established execution first, after which the flaw provided SYSTEM privileges and enabled FudModule to interfere with security telemetry and code-integrity controls. Separate reporting says CVE-2025-49113 enabled authenticated PHP object deserialisation and remote code execution on Roundcube servers subsequently used as concealed command-and-control infrastructure.
Recommended defensive actions
- Apply the August 2026 Microsoft security updates to all affected Windows workstations and servers, prioritising endpoints used by defence, aerospace, aviation and recruitment-facing personnel.
- Upgrade Roundcube Webmail to at least 1.5.10 or 1.6.11 and investigate previously exposed or unpatched installations for unauthorised files, PHP web shells and account compromise.
- Hunt for unexpected libmupdf.dll side-loading, SecurityPDF installations, MISTPEN execution, unusual msiexec.exe child activity and security-telemetry disruption on Windows endpoints.
- Block the reported impersonation domains envell[.]xyz, enveββil[.]online and uxtramine[.]org after validating that they have no legitimate organisational use.
- Monitor Microsoft Graph API and OneDrive traffic for anomalous module retrieval by non-standard processes, while preserving legitimate business use.
- Verify software through vendor-controlled distribution channels rather than search rankings or links supplied by purported recruiters.
Uncertainties and evidence gaps
- The original Check Point research page returned an access-denied response during verification, so detailed malware findings and victimology could be assessed only through multiple reports quoting that research.
- The public evidence reviewed does not disclose the number or identities of compromised organisations.
- It remains unclear how the reported Enveil impersonation websites were incorporated into each victim's social-engineering sequence.
- No public proof-of-concept or exploit repository for CVE-2026-68820 was identified, but absence from the reviewed sources does not prove that code is unavailable privately.
- CISA confirms exploitation of CVE-2026-68820 but does not independently attribute that exploitation to Lazarus; the attribution derives from Check Point's investigation.
Vulnerability flow
Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.
Confirmed active exploitation of CVE-2026-68820; CVE-2025-49113 was reportedly exploited to compromise Roundcube infrastructure supporting the campaign, while no public PoC for CVE-2026-68820 was identified.
The investigation separated the exploited Windows privilege-escalation vulnerability from the social-engineering campaign and the separate Roundcube flaw used against supporting infrastructure. Microsoft, NVD and CISA establish the weakness, affected scope, patch availability and exploitation status, while three security publications consistently describe Lazarus attribution and the Operation Dream Job infection chains. The direct Check Point publication could not be accessed, reducing confidence in granular attribution, victimology and malware details from high to medium.
- What event and claims were being reported?Reviewed the supplied report and followed its references to the campaign research and Microsoft vulnerability record.thehackernews.com β
The report attributes exploitation of CVE-2026-68820 to Lazarus during Operation Dream Job and describes two social-engineering chains, FudModule privilege escalation, new Troy malware and compromised infrastructure.
why This framed the event but remained secondary reporting requiring confirmation from vendor and government records.
- Could the original campaign investigation be verified directly?Opened the linked Check Point research publication.blog.checkpoint.com β
The site returned an HTTP 403 access-denied page, preventing direct examination of the original technical evidence.
why This creates a material attribution and detail-verification limitation despite consistent downstream reporting.
- Does Microsoft recognise CVE-2026-68820 and provide a fix?Opened Microsoft's Security Update Guide record.msrc.microsoft.com β
Microsoft maintains a vendor security record for CVE-2026-68820 associated with the August 2026 security release.
why This confirms the identifier and vendor remediation source rather than relying on the original article.
- Is exploitation independently confirmed in the wild?Reviewed CISA's filtered Known Exploited Vulnerabilities catalogue entry.cisa.gov β
CISA lists the AFD.sys use-after-free vulnerability as known exploited, added 11 August 2026, with remediation due 25 August 2026 for covered federal organisations.
why This supports confirmed active exploitation, although CISA does not attribute the activity to Lazarus.
- What are the vulnerability prerequisites, severity and affected configurations?Reviewed the National Vulnerability Database record for CVE-2026-68820.nvd.nist.gov β
NVD describes a local use-after-free requiring low privileges, with high complexity, no user interaction at the exploitation stage, CVSS 7.0 and broad impact across Windows client and server releases.
why This establishes that CVE-2026-68820 is a post-compromise elevation flaw rather than the campaign's remote entry point.
- Is the campaign account corroborated outside the supplied article?Reviewed separate reporting focused on the Lazarus and FudModule activity.cybersecuritynews.com β
The publication independently reports the same Lazarus attribution, defence and aerospace targeting, DLL side-loading and SecurityPDF chains, MISTPEN delivery and SYSTEM-level FudModule deployment.
why The consistency strengthens the campaign assessment, although the report also relies substantially on Check Point's investigation.
- Is exploitation and patch timing corroborated independently of campaign-focused coverage?Reviewed Help Net Security's August 2026 Patch Tuesday analysis.helpnetsecurity.com β
The analysis confirms that Microsoft patched CVE-2026-68820 in August 2026, describes it as exploited in zero-day attacks and states that a locally authenticated low-privileged attacker can reach SYSTEM without user interaction at that stage.
why This corroborates the core vulnerability facts and exploitation status from another domain.
- How does CVE-2025-49113 relate to this story?Reviewed the NVD record for the Roundcube vulnerability named in infrastructure reporting.nvd.nist.gov β
Roundcube before 1.5.10 and 1.6.x before 1.6.11 permits authenticated remote code execution through PHP object deserialisation and is listed as known exploited.
why This confirms the technical and affected-version claims; campaign reporting links the flaw to compromised Roundcube command-and-control servers rather than Windows endpoint elevation.
Research coverage
All 68 registered source leaves were evaluated for this run: 61 completed, 0 were unavailable, 0 failed and 7 were disabled. For this story, 5 registered sources supplied useful evidence (3 primary, 1 corroborating, 1 contextual and 0 PoC/exploit references). 56 completed sources contained no matched information for this story.
Complete source-by-source audit 68 sources
| Source | Run result | Value | Why it was useful β or not |
|---|---|---|---|
| CISA KEVkev | ok1665 records | Primary evidence3 matched items | Confirmed that a related CVE is listed in CISA's Known Exploited Vulnerabilities catalogue. Supplied a vendor or government advisory opened and verified during focused research. |
| NVDcve | ok900 records | Primary evidence2 matched items | Supplied a vendor or government advisory opened and verified during focused research. |
| The Hacker Newsnews | ok10 records | Primary evidence1 matched items | Published the source report used to frame and date the event. |
| CISA Alertsnews | ok empty0 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| FIRST EPSSepss | ok7602 records | Context2 matched items | Added exploitation-probability context; EPSS does not itself prove exploitation. |
| AlienVault OTXdark_web | ok10 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| BleepingComputernews | ok11 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| CIRCL CVEcve | ok30 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Cisco PSIRTvendor_advisory | ok5324 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Cisco Talosnews | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| deepdarkCTI CVE most exploiteddeepdarkcti | ok94 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Discorddeepdarkcti | ok7 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI exploitsdeepdarkcti | ok24 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI forumsdeepdarkcti | ok264 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware as a servicedeepdarkcti | ok7 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware samplesdeepdarkcti | ok3 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI marketsdeepdarkcti | ok127 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI phishingdeepdarkcti | ok19 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI ransomware gangsdeepdarkcti | ok682 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI RATsdeepdarkcti | ok1 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram infostealerdeepdarkcti | ok130 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram threat actorsdeepdarkcti | ok1008 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Twitter threat actorsdeepdarkcti | ok39 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| DNSDumpster domain IOC enrichmentresearch | ok1 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Exploit-DBexploit_reference | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| Fortinet PSIRTvendor_advisory | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| GitHub topic: cveresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| GitHub topic: exploitresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| GitHub topic: penetration-testingresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| GitHub topic: pocresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| GitHub topic: vulnerabilityresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| GreyNoiseexploit_reference | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| KrebsOnSecuritynews | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| LinkedIn RSS proxy feeds (disabled)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| MalwareBazaardark_web | ok8 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cveresearch | ok20 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cybersecurityresearch | ok12 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #exploitresearch | ok20 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #infosecresearch | ok19 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #malwareresearch | ok20 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #ransomwareresearch | ok20 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #threatintelresearch | ok13 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Mastodon #vulnerabilityresearch | ok20 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Metasploit module metadataexploit_reference | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| Microsoft MSRCvendor_advisory | ok1590 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Microsoft Securitynews | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| MISP Galaxyresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| MISP threat actor galaxyactor | ok0 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Palo Alto Networks PSIRTvendor_advisory | ok25 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| ProjectDiscovery nuclei templatesexploit_reference | ok1 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Rapid7news | ok1 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Reddit r/AskNetsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/cybersecurity (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/malware (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/netsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/ReverseEngineering (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| SANS ISCnews | ok1 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Shadowserver public aggregate honeypot observationsexploit_reference | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| Shodanresearch | ok6 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Sigma Rulesresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| Sophos IOCsresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| ThreatFoxthreat_intelligence | ok100 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| UK NCSCnews | ok1 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Unit42 IOCsresearch | ok empty0 records | Checked β no match | The source completed but returned no records in the collection scope. |
| URLhausdark_web | ok10 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| VirusTotal Community IOC enrichmentresearch | ok4 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| VulnCheck KEVkev | ok500 records | Checked β no match | The source completed, but none of its retained records matched this story. |
| Vulnerability Lookupcve | ok30 records | Checked β no match | The source completed, but none of its retained records matched this story. |
Additional verified pages 12 opened outside the registered collection
Vulnerability & exploitation4
Vendor & gov advisories4
Microsoft's vendor record for the patched Windows Ancillary Function Driver for WinSock vulnerability.
Confirms exploitation in the wild, with a remediation deadline of 25 August 2026 for affected US federal organisations.
Records the local use-after-free flaw, CVSS 7.0 assessment, affected Windows configurations and Known Exploited Vulnerabilities status.
Confirms authenticated remote code execution in Roundcube before 1.5.10 and 1.6.11, relevant to the reportedly hijacked command-and-control servers.
Analysis & research3
Detailed reporting on the Lazarus attribution, Operation Dream Job delivery chains, malware and affected sectors.
Corroborates the reported campaign mechanics, targeted sectors and post-exploitation use of FudModule.
Independently corroborates the Windows flaw's exploitation, local prerequisites and August 2026 patch release.