Lazarus Cyber Attack
2026-08-14 04:05:20

New Cyber Attack from North Korea's Lazarus Group Targeting Defense Sector

New Threat Unveiled



In recent investigations by Check Point Research (CPR), a unit of Check Point Software Technologies, a new cyber campaign known as Operation Dream Job has been identified. This operation is orchestrated by the North Korean state-sponsored threat group Lazarus and focuses on deceiving professionals in the defense and aerospace sectors. The group employs fake job advertisements to lure targets into malicious actions, particularly in Europe and India.

Key Findings



CPR has confirmed that Lazarus is exploiting a previously unknown vulnerability in Windows denoted as CVE-2026-68820. This allows the attackers to take complete control of infected systems while evading detection through Endpoint Detection and Response (EDR) systems. The vulnerability was responsibly disclosed by Check Point and scheduled for a fix in the upcoming Patch Tuesday on August 11, 2026.

Victims are approached by purported recruitment agents who entice them into opening harmful PDF documents or installing a Trojanized PDF viewer. This viewer secretly installs a newly identified backdoor, granting attackers remote access to compromised computers.

Instead of managing their own servers, the attackers hijack legitimate compromised websites and webmail servers to facilitate command relay, which obscures malicious traffic against regular activities.

The Mechanics of Operation Dream Job



Since early 2026, CPR has tracked this campaign targeting professionals in the defense and aerospace sectors, where interest in attractive job offers is leveraged. Lazarus attackers masquerade as recruiters on platforms like LinkedIn or messaging apps, presenting positions from renowned firms to lure victims into downloading malicious content. This method, while simple, effectively targets career ambitions and employs sophisticated social engineering.

Trust as a Weapon



This campaign begins with spear phishing disguised as enticing job offers from defense giants like Lockheed Martin and privacy technology firm Enveil. At least three fraudulent Enveil websites, optimized for SEO, emerged in the process, allowing attackers to appear legitimate in search engine results, directing victims to download malware instead.

Documents masquerading as job postings from Lockheed Martin were delivered through PDFs, demonstrating that traditional indicators to identify phishing attempts are becoming ineffective. Users must remain vigilant, recognizing that even search results and download sources may be compromised.

New Tools and Evolving Techniques



The use of a Trojan, dubbed Troy, is noted, concealed as a PDF viewer called SecurityPDF. This marks the first public acknowledgment of a modular backdoor supporting 17 operator commands. Furthermore, the new version of FudModule (v3.1) exploits zero-day vulnerabilities affecting AFD.sys to obtain SYSTEM privileges and disable EDR security tools. This progression of tactics illustrates an adaptability in the attackers' toolkit to bypass detection used by defense organizations.

International Implications



Lazarus's campaign has had global ramifications, targeting the defense sector across France, Germany, Brazil, and India. The latter is of particular concern due to its booming defense and aerospace industry, making it a primary target.

Exploiting Genuine Infrastructure



Rather than using dedicated servers, Lazarus now utilizes compromised legitimate webmail services like Roundcube or content management systems (CMS) to conduct its operations. By leveraging vulnerabilities that have already been patched, alongside credentials obtained from dark web leaks, these entities repurpose at least 17 compromised servers for command and control.

An Escalating Threat



An illustration of this tactic occurred in France, where a compromised organization was commandeered to amplify spear phishing attacks globally. By leveraging the credibility of a real entity, the attackers enhanced the trustworthiness of their operations, revealing that corporate breaches have now broader implications.

Sergey Shykevich, the director of threat intelligence at Check Point, remarked, “This campaign is perilous not merely because of the zero-day vulnerabilities but also due to Lazarus integrating already trusted infrastructure at all phases of the attack. With the convergence of legitimate vendors, compromised organizations, and search result manipulation, traditional advice on spotting phishing links is becoming obsolete.”

Conclusion



In today’s cyber landscape, where authenticity can be forged, it’s critical to maintain a zero trust mindset. Users are encouraged to apply due diligence in verifying software updates through official channels and to approach familiar websites with caution, as trust can no longer be assumed. Maintaining secure practices could mitigate potential threats in an increasingly complex cyber environment.


画像1

画像2

画像3

Topics Other)

【About Using Articles】

You can freely use the title and article content by linking to the page where the article is posted.
※ Images cannot be used.

【About Links】

Links are free to use.