Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Guardian view on Japan’s yen: Trump wants to keep the easy-money machine running | Editorial

    August 12, 2026

    Live Updates: First Total Eclipse in Europe in Decades Turns Day to Night

    August 12, 2026

    Sparky Linux just restored 32-bit support – why that still matters

    August 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Guardian view on Japan’s yen: Trump wants to keep the easy-money machine running | Editorial
    • Live Updates: First Total Eclipse in Europe in Decades Turns Day to Night
    • Sparky Linux just restored 32-bit support – why that still matters
    • Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
    • Bitcoin Flashes Bottom Signals As “Digital Gold” Narrative Returns
    • A vest tested on the Artemis I mission blocked some radiation exposure
    • As DRC confronts largest Ebola outbreak, health agencies revise strategy
    • $13.2 billion gas project moves forward with ADNOC’s $8.2B EPC awards to Wison and Maire’s Tecnimont
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 12, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 12, 2026Vulnerability / Cyber Espionage

    The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.

    The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and social engineering campaign orchestrated by Pyongyang-backed hackers to target professionals worldwide with fake-but-compelling job offers at firms like Lockheed Martin and Enveil to steal sensitive data and install malware by approaching them on platforms like LinkedIn, pretending to be recruiters in an attempt to build trust.

    The attacks have been found to exploit CVE-2026-68820 (CVSS score: 7.0), a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock (“AFD.sys”) that was patched by Microsoft as part of its Patch Tuesday updates for August 2026.

    As observed in prior campaign waves, victims are lured through bogus recruiter messages and tricked into opening a malicious PDF or installing a trojanized PDF viewer, which is then used to install a new backdoor called Troy that grants remote access to the compromised machine. The end goal of these intrusions is to seize complete control of infected computers and bypass security controls.

    Cybersecurity

    The use of a trojanized PDF viewer is a tried-and-tested tactic adopted by the Lazarus Group in conjunction with Dream Job, with the threat actors abusing this method as far back as 2022.

    Two different parallel infection sequences have been detected as part of the latest attacks –

    • DLL side-loading, in which victims are instructed to download an encrypted archive that’s used to trigger a DLL side-loading chain. The malicious DLL (“libmupdf.dll”) is used to display a bogus job description lure, while it stealthily downloads and executes in memory a lightweight downloader dubbed MISTPEN. The downloader communicates with threat actor-controlled infrastructure using Microsoft Graph API and OneDrive to retrieve and run reconnaissance and persistence modules and trigger the “AFD.sys” driver exploit, before deploying ForestTiger (aka ScoringMathTea), which provides remote access to the host.
    • Trojanized “SecurityPDF” PDF viewer, in which victims are instructed to download SecurityPDF from a website impersonating Enveil. Once installed, it monitors for any PDF document opened through it for a special marker (“This document is encrypted with sumatrapdf reader!!!!!!!!!!!!”). If such a marker is present, the application decrypts and launches an embedded payload that’s responsible for loading a backdoor called Troy directly into memory. The DLL implant supports 17 operator commands to facilitate file enumeration, upload and download, archive and exfiltration, interactive shell access, process termination, in-memory DLL injection, and configuration updates.
    High-level overview of the DLL sideloading infection chain.

    MISTPEN, for its part, loads at least four different modules –

    • GetInfoPlugin (“Release_GetInfoPlugin_x64.dll”), to profile the host and exfiltrate the collected information as a single wide-character string
    • PvPlugin (“Release_PvPlugin_x64.dll”), to collect host reconnaissance data and details about running processes
    • OneScreenCapture (“OneScreenCapture64.dll”), to take screenshots of the current desktop, including all monitors, and transmit them as JPEG images
    • LPE (local privilege escalation) loader, which gathers host information, generates new key material using the ML-KEM post-quantum key encapsulation algorithm, and uses the negotiated key during the handshake process to decrypt and run FudModule.

    The attack chain employs an updated version of the known kernel-mode rootkit the Lazarus Group has repeatedly employed since at least 2022 to conceal the presence of malicious tools from security software installed on the host.

    One of websites that rank highly in search engine results for “Enveil SecurityPDF”

    Specifically, it exploits a local privilege escalation vulnerability in “AFD.sys,” obtains SYSTEM privileges, and ultimately injects another instance of MISTPEN into a SYSTEM process so as to allow it to run with elevated privileges and away from the eyes of security tools. The newer version, called FudModule 3.1, improves upon its predecessor by allowing it to tamper with a Windows feature called Smart App Control designed to verify if a program is safe to run.

    “Within the SYSTEM-level msiexec.exe child process, its remote stub sets VerifiedAndReputablePolicyState to zero and invokes NtSetSystemInformation class 0xA4 with option 0x10000000, triggering an in-place reload of the code integrity policy,” Check Point said.

    What’s more, the attackers are said to have created at least three websites impersonating Enveil to distribute “SecurityPDF,” although it’s unclear how these fake portals were incorporated into the social engineering campaign. It’s suspected that the adversary first sends the PDF through a phishing message and then urges them to download the PDF viewer from the site to view the document.

    The domain names are listed below –

    • envell[.]xyz
    • enveil[.]online
    • uxtramine[.]org

    What’s notable is that the campaign, instead of spinning up its own bespoke infrastructure, hijacks legitimate but compromised WordPress and SharePoint websites and vulnerable Roundcube webmail servers for use as ForestTiger command-and-control (C2) servers, thereby making it a lot more challenging to differentiate it from normal web traffic.

    Cybersecurity

    Many of the Roundcube servers have been found to be vulnerable to CVE-2025-49113, with the attackers leveraging it to infect them with a previously undocumented PHP web shell codenamed RelayShell to enable the exchange of commands and responses in the form of text files. In at least one case, an already breached France-based organization was used to send phishing messages to new victims to bypass reputation-based filters.

    The latest findings show that Lazarus Group continues to hone its malware capabilities and tradecraft, while keeping the foundations of Dream Job largely intact in attacks aimed at critical sectors across the world.

    “What makes this campaign so dangerous is not only the zero-day vulnerability – but also how Lazarus wove legitimate, trusted infrastructure into every stage of the attack,” Sergey Shykevich, director of threat intelligence at Check Point Software, said in a statement shared with The Hacker News. “They hid in plain sight, behind top-ranked search results, real vendor branding, and the reputation of organizations they had already compromised.

    “When the website, the download and the recruiter all appear authentic, the old advice to ‘spot the phishing link’ is no longer easily applicable. Staying safe now means assuming that trust itself can be counterfeited: patch the moment updates land, verify software through official channels rather than search rankings, and extend zero-trust thinking to the legitimate-looking sites and partners we interact with every day.”

    access Backdoor Deploy exploits gain Lazarus System Windows ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

    737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

    Mindgard Raises $30 Million to Protect AI Systems

    SharePoint Vulnerability Exploited Shortly After PoC Release

    17 old software bugs that took way too long to squash

    The AI harness is the new attack surface

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Guardian view on Japan’s yen: Trump wants to keep the easy-money machine running | Editorial

    August 12, 2026

    Live Updates: First Total Eclipse in Europe in Decades Turns Day to Night

    August 12, 2026

    Sparky Linux just restored 32-bit support – why that still matters

    August 12, 2026

    Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

    August 12, 2026
    Latest Posts

    Record-breaking wildfires burned nearly 100,000 hectares in France, interior minister says – POLITICO

    July 25, 2026

    Former top US food safety official says Trump’s handling of cyclospora is ‘catastrophic’ | Trump administration

    July 25, 2026

    Did Trump collapse while trying to get into vehicle?

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Guardian view on Japan’s yen: Trump wants to keep the easy-money machine running | Editorial

    August 12, 2026

    Live Updates: First Total Eclipse in Europe in Decades Turns Day to Night

    August 12, 2026

    Sparky Linux just restored 32-bit support – why that still matters

    August 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.