Find notable cyber news and cases, enriched with sources, timelines, and signals.

Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India

Campaign
First reported
Last updated
Happening score
H score 22
2 unique sources, 2 articles

Summary

Hide ▲

Lazarus expanded Operation Dream Job into a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India, with successful targeting also observed in France, Germany, and Brazil. The activity used fraudulent recruitment offers and abused compromised Roundcube instances to hide communications, while Check Point tied the latest wave to Troy, RelayShell, and a FudModule variant that incorporated CVE-2026-68820. Microsoft patched CVE-2026-68820 in this month's Patch Tuesday and marked it actively exploited. Check Point also reported that the exploit supported Windows 11 builds 26100 and 26200 and that at least 17 servers were infected with RelayShell.

Related Happenings

Microsoft August 2026 Patch Tuesday security updates (3 zero-days)

Security Patch Release
H score39 First: 11.08.2026 21:08 Last: 11.08.2026 21:08 Sources 1

How related: CVE-2026-68820 is a use-after-free race condition in AFD.sys, the driver handling network sockets in the Windows kernel, and was the only flaw in this the August Patch Tuesday release Microsoft flagged as under active exploitation.

About this happening: Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in AFD.sys that is under active ex...

Latest development: 12.08.2026 16:35

Lazarus group malware used a post-quantum key exchange to negotiate its command channel, then pulled down a Windows zero-day exploit in an Operation Dream Job campaign against defense and aerospace companies in Europe and India. The chain ran through MISTPEN, an in-memory downloader that fetched FudModule v3.1, a kernel rootkit that disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger, blinds 94 ETW providers, and tampers with Smart App Control; the same infrastructure also used RelayShell and impersonation sites for Enveil to distribute Troy.

Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia

Campaign
H score32 First: 28.07.2026 14:55 Last: 28.07.2026 14:55 Sources 1

About this happening: Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve ...

Earth Lusca Operation FishMedley espionage campaign

Campaign
H score38 First: 16.06.2026 12:44 Last: 16.06.2026 12:44 Sources 1

About this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...

Webworm multi-country targeting campaign against government and enterprise victims

Campaign
H score38 First: 20.05.2026 15:51 Last: 20.05.2026 15:51 Sources 1

About this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...

ClockRemoval.ps1 antivirus-disabling malware activity linked to Dragon Boss Solutions LLC

Malware Activity
H score25 First: 15.04.2026 17:40 Last: 15.04.2026 17:40 Sources 1

About this happening: A signed software operation linked to Dragon Boss Solutions LLC was observed using ClockRemoval.ps1 to disable antivirus on more than 23,000 endpoints worldwide, raisi...

Timeline

  1. 12.08.2026 18:38 1 articles · 0h ago

    Lazarus broadens Operation Dream Job with Troy, RelayShell, and Roundcube abuse

    Campaign Scope Update

    Lazarus broadened the Operation Dream Job campaign against defense, aerospace, and aviation organizations in Europe and India by using fraudulent recruitment offers, with successful targeting also observed in Western Europe, including France and Germany, and activity extending into South America, including Brazil. Check Point also tied the latest wave to the Troy backdoor, a FudModule variant with a CVE-2026-68820 exploit, and compromised Roundcube instances used to hide malicious communications and deploy the RelayShell web shell.

    Show sources
  2. 12.08.2026 16:35 1 articles · 2h ago

    Microsoft ships the August Patch Tuesday fix for CVE-2026-68820

    Mitigation Patch Update

    Microsoft shipped the August Patch Tuesday fix for CVE-2026-68820, a use-after-free race condition in AFD.sys, and flagged it as the only flaw in that release under active exploitation.

    Show sources
  3. 28.07.2026 03:00 2 articles · 15d ago

    Check Point reports CVE-2026-68820 to Microsoft

    Initial Disclosure

    Check Point Research reported CVE-2026-68820, a use-after-free race condition in AFD.sys, to Microsoft after connecting it to Lazarus activity against defense and aerospace companies in Europe and India.

    Show sources