Find notable cyber news and cases, enriched with sources, timelines, and signals.

Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India

Campaign
First reported
Last updated
Happening score
H score 22
3 unique sources, 3 articles

Summary

Hide ▲

Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India, with successful targeting also observed in France, Germany, and Brazil. The activity used fraudulent recruitment offers and LinkedIn recruiter impersonation, then delivered Troy and a FudModule variant that incorporated CVE-2026-68820 and abuse of compromised Roundcube infrastructure. Microsoft patched CVE-2026-68820 in the August 2026 Patch Tuesday and marked it actively exploited. Check Point also reported RelayShell use on at least 17 servers and described additional delivery paths through MISTPEN, DLL sideloading, and a trojanized PDF viewer.

Related Happenings

Microsoft August 2026 Patch Tuesday security updates (3 zero-days)

Security Patch Release
H score39 First: 11.08.2026 21:08 Last: 11.08.2026 21:08 Sources 1

How related: CVE-2026-68820 is a use-after-free race condition in AFD.sys, the driver handling network sockets in the Windows kernel, and was the only flaw in this the August Patch Tuesday release Microsoft flagged as under active exploitation.

About this happening: Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in AFD.sys that is under active ex...

Latest development: 12.08.2026 16:35

Lazarus group malware used a post-quantum key exchange to negotiate its command channel, then pulled down a Windows zero-day exploit in an Operation Dream Job campaign against defense and aerospace companies in Europe and India. The chain ran through MISTPEN, an in-memory downloader that fetched FudModule v3.1, a kernel rootkit that disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger, blinds 94 ETW providers, and tampers with Smart App Control; the same infrastructure also used RelayShell and impersonation sites for Enveil to distribute Troy.

Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia

Campaign
H score32 First: 28.07.2026 14:55 Last: 28.07.2026 14:55 Sources 1

About this happening: Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve ...

The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster

Threat Actor Meta
H score14 First: 13.07.2026 18:30 Last: 13.07.2026 18:30 Sources 1

About this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...

Earth Lusca Operation FishMedley espionage campaign

Campaign
H score38 First: 16.06.2026 12:44 Last: 16.06.2026 12:44 Sources 1

About this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...

TA4922 expanded European phishing-and-malware campaign

Campaign
H score40 First: 04.06.2026 00:45 Last: 04.06.2026 00:45 Sources 1

About this happening: TA4922 is a China-linked cybercrime campaign that now also uses the Cruciferra crypter, while continuing its income tax-themed phishing activity against Indian t...

Timeline

  1. 12.08.2026 18:38 2 articles · 13d ago

    Lazarus broadens Operation Dream Job with Troy, RelayShell, and Roundcube abuse

    Campaign Scope Update

    Lazarus broadened the Operation Dream Job campaign against defense, aerospace, and aviation organizations in Europe and India by using fraudulent recruitment offers, with successful targeting also observed in Western Europe, including France and Germany, and activity extending into South America, including Brazil. Check Point also tied the latest wave to the Troy backdoor, a FudModule variant with a CVE-2026-68820 exploit, and compromised Roundcube instances used to hide malicious communications and deploy the RelayShell web shell.

    Show sources
  2. 12.08.2026 16:35 1 articles · 13d ago

    Microsoft ships the August Patch Tuesday fix for CVE-2026-68820

    Mitigation Patch Update

    Microsoft shipped the August Patch Tuesday fix for CVE-2026-68820, a use-after-free race condition in AFD.sys, and flagged it as the only flaw in that release under active exploitation.

    Show sources
  3. 28.07.2026 03:00 2 articles · 29d ago

    Check Point reports CVE-2026-68820 to Microsoft

    Initial Disclosure

    Check Point Research reported CVE-2026-68820, a use-after-free race condition in AFD.sys, to Microsoft after connecting it to Lazarus activity against defense and aerospace companies in Europe and India.

    Show sources