Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-13 ยท updated: 2026-08-13 ยท tags: [incident, apt, lazarus, north-korea, zero-day, operation-dream-job, microsoft, windows, backdoor, defense-aerospace] ยท confidence: high ยท affected_sectors: [defence, aerospace, technology, government] ยท au_impact: true

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Check Point Research has attributed exploitation of CVE-2026-68820 โ€” the afd.sys WinSock driver use-after-free patched in Microsoft's August 2026 Patch Tuesday release โ€” to the Lazarus Group's Operation Dream Job campaign. The North Korean state-sponsored group used the privilege-escalation flaw to gain SYSTEM access and deliver a never-before-seen backdoor against defence and aerospace companies in France, Germany, Brazil and India.

Key Facts

Attribute Detail
Actor Lazarus Group (DPRK), Operation Dream Job
Vulnerability CVE-2026-68820 (afd.sys), CVSS 7.0 โ€” see Cve 2026 68820 Afd Sys Winsock Uaf
Targets Defence and aerospace companies in FR, DE, BR, IN
TTPs Fake job offers on LinkedIn; malware delivery; local escalation to SYSTEM
Other attribution Same flaw added to CISA KEV on 2026-08-11 (BOD 26-04)
CISA directive Federal civilian agencies given two weeks to remediate

Context

Operation Dream Job is Lazarus's long-running espionage and social-engineering campaign using fake-but-compelling job offers to target professionals, blending credential theft with backdoor deployment. The afd.sys exploitation means the August Patch Tuesday release should be treated as urgent across AU/NZ Windows estates (Essential Eight, NZISM patching expectations), and CISA's two-week federal remediation deadline is a reasonable benchmark for agencies.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-13