Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India
Campaign
Summary
Hide ▲
Show ▼
Lazarus expanded Operation Dream Job into a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India, with successful targeting also observed in France, Germany, and Brazil. The activity used fraudulent recruitment offers and abused compromised Roundcube instances to hide communications, while Check Point tied the latest wave to Troy, RelayShell, and a FudModule variant that incorporated CVE-2026-68820. Microsoft patched CVE-2026-68820 in this month's Patch Tuesday and marked it actively exploited. Check Point also reported that the exploit supported Windows 11 builds 26100 and 26200 and that at least 17 servers were infected with RelayShell.
Related Happenings
Microsoft August 2026 Patch Tuesday security updates (3 zero-days)
Security Patch Release
H score39
First: 11.08.2026 21:08
Last: 11.08.2026 21:08
Sources 1
How related:
CVE-2026-68820 is a use-after-free race condition in AFD.sys, the driver handling network sockets in the Windows kernel, and was the only flaw in this the August Patch Tuesday release Microsoft flagged as under active exploitation.
About this happening:
Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in AFD.sys that is under active ex...
Microsoft August 2026 Patch Tuesday security updates (3 zero-days)
Security Patch ReleaseHow related: CVE-2026-68820 is a use-after-free race condition in AFD.sys, the driver handling network sockets in the Windows kernel, and was the only flaw in this the August Patch Tuesday release Microsoft flagged as under active exploitation.
About this happening: Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in AFD.sys that is under active ex...
Latest development: 12.08.2026 16:35
Lazarus group malware used a post-quantum key exchange to negotiate its command channel, then pulled down a Windows zero-day exploit in an Operation Dream Job campaign against defense and aerospace companies in Europe and India. The chain ran through MISTPEN, an in-memory downloader that fetched FudModule v3.1, a kernel rootkit that disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger, blinds 94 ETW providers, and tampers with Smart App Control; the same infrastructure also used RelayShell and impersonation sites for Enveil to distribute Troy.
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
Campaign
H score32
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
About this happening:
Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve ...
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
CampaignAbout this happening: Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve ...
Earth Lusca Operation FishMedley espionage campaign
Campaign
H score38
First: 16.06.2026 12:44
Last: 16.06.2026 12:44
Sources 1
About this happening:
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Earth Lusca Operation FishMedley espionage campaign
CampaignAbout this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Webworm multi-country targeting campaign against government and enterprise victims
Campaign
H score38
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Webworm multi-country targeting campaign against government and enterprise victims
CampaignAbout this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
ClockRemoval.ps1 antivirus-disabling malware activity linked to Dragon Boss Solutions LLC
Malware Activity
H score25
First: 15.04.2026 17:40
Last: 15.04.2026 17:40
Sources 1
About this happening:
A signed software operation linked to Dragon Boss Solutions LLC was observed using ClockRemoval.ps1 to disable antivirus on more than 23,000 endpoints worldwide, raisi...
ClockRemoval.ps1 antivirus-disabling malware activity linked to Dragon Boss Solutions LLC
Malware ActivityAbout this happening: A signed software operation linked to Dragon Boss Solutions LLC was observed using ClockRemoval.ps1 to disable antivirus on more than 23,000 endpoints worldwide, raisi...
Timeline
-
12.08.2026 18:38 1 articles · 0h ago
Lazarus broadens Operation Dream Job with Troy, RelayShell, and Roundcube abuse
Campaign Scope UpdateLazarus broadened the Operation Dream Job campaign against defense, aerospace, and aviation organizations in Europe and India by using fraudulent recruitment offers, with successful targeting also observed in Western Europe, including France and Germany, and activity extending into South America, including Brazil. Check Point also tied the latest wave to the Troy backdoor, a FudModule variant with a CVE-2026-68820 exploit, and compromised Roundcube instances used to hide malicious communications and deploy the RelayShell web shell.
Show sources
- Lazarus hackers exploited Windows zero-day to target defense firms — www.bleepingcomputer.com — 12.08.2026 18:38
-
12.08.2026 16:35 1 articles · 2h ago
Microsoft ships the August Patch Tuesday fix for CVE-2026-68820
Mitigation Patch UpdateMicrosoft shipped the August Patch Tuesday fix for CVE-2026-68820, a use-after-free race condition in AFD.sys, and flagged it as the only flaw in that release under active exploitation.
Show sources
- Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day — www.infosecurity-magazine.com — 12.08.2026 16:35
-
28.07.2026 03:00 2 articles · 15d ago
Check Point reports CVE-2026-68820 to Microsoft
Initial DisclosureCheck Point Research reported CVE-2026-68820, a use-after-free race condition in AFD.sys, to Microsoft after connecting it to Lazarus activity against defense and aerospace companies in Europe and India.
Show sources
- Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day — www.infosecurity-magazine.com — 12.08.2026 16:35
- Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day — www.infosecurity-magazine.com — 12.08.2026 16:35