Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India
Campaign
Summary
Hide ▲
Show ▼
Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India, with successful targeting also observed in France, Germany, and Brazil. The activity used fraudulent recruitment offers and LinkedIn recruiter impersonation, then delivered Troy and a FudModule variant that incorporated CVE-2026-68820 and abuse of compromised Roundcube infrastructure. Microsoft patched CVE-2026-68820 in the August 2026 Patch Tuesday and marked it actively exploited. Check Point also reported RelayShell use on at least 17 servers and described additional delivery paths through MISTPEN, DLL sideloading, and a trojanized PDF viewer.
Related Happenings
Microsoft August 2026 Patch Tuesday security updates (3 zero-days)
Security Patch Release
H score39
First: 11.08.2026 21:08
Last: 11.08.2026 21:08
Sources 1
How related:
CVE-2026-68820 is a use-after-free race condition in AFD.sys, the driver handling network sockets in the Windows kernel, and was the only flaw in this the August Patch Tuesday release Microsoft flagged as under active exploitation.
About this happening:
Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in AFD.sys that is under active ex...
Microsoft August 2026 Patch Tuesday security updates (3 zero-days)
Security Patch ReleaseHow related: CVE-2026-68820 is a use-after-free race condition in AFD.sys, the driver handling network sockets in the Windows kernel, and was the only flaw in this the August Patch Tuesday release Microsoft flagged as under active exploitation.
About this happening: Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in AFD.sys that is under active ex...
Latest development: 12.08.2026 16:35
Lazarus group malware used a post-quantum key exchange to negotiate its command channel, then pulled down a Windows zero-day exploit in an Operation Dream Job campaign against defense and aerospace companies in Europe and India. The chain ran through MISTPEN, an in-memory downloader that fetched FudModule v3.1, a kernel rootkit that disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger, blinds 94 ETW providers, and tampers with Smart App Control; the same infrastructure also used RelayShell and impersonation sites for Enveil to distribute Troy.
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
Campaign
H score32
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
About this happening:
Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve ...
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
CampaignAbout this happening: Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve ...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor Meta
H score14
First: 13.07.2026 18:30
Last: 13.07.2026 18:30
Sources 1
About this happening:
The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor MetaAbout this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
Earth Lusca Operation FishMedley espionage campaign
Campaign
H score38
First: 16.06.2026 12:44
Last: 16.06.2026 12:44
Sources 1
About this happening:
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Earth Lusca Operation FishMedley espionage campaign
CampaignAbout this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
TA4922 expanded European phishing-and-malware campaign
Campaign
H score40
First: 04.06.2026 00:45
Last: 04.06.2026 00:45
Sources 1
About this happening:
TA4922 is a China-linked cybercrime campaign that now also uses the Cruciferra crypter, while continuing its income tax-themed phishing activity against Indian t...
TA4922 expanded European phishing-and-malware campaign
CampaignAbout this happening: TA4922 is a China-linked cybercrime campaign that now also uses the Cruciferra crypter, while continuing its income tax-themed phishing activity against Indian t...
Timeline
-
12.08.2026 18:38 2 articles · 13d ago
Lazarus broadens Operation Dream Job with Troy, RelayShell, and Roundcube abuse
Campaign Scope UpdateLazarus broadened the Operation Dream Job campaign against defense, aerospace, and aviation organizations in Europe and India by using fraudulent recruitment offers, with successful targeting also observed in Western Europe, including France and Germany, and activity extending into South America, including Brazil. Check Point also tied the latest wave to the Troy backdoor, a FudModule variant with a CVE-2026-68820 exploit, and compromised Roundcube instances used to hide malicious communications and deploy the RelayShell web shell.
Show sources
- Lazarus hackers exploited Windows zero-day to target defense firms — www.bleepingcomputer.com — 12.08.2026 18:38
- Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor — thehackernews.com — 12.08.2026 20:39
-
12.08.2026 16:35 1 articles · 13d ago
Microsoft ships the August Patch Tuesday fix for CVE-2026-68820
Mitigation Patch UpdateMicrosoft shipped the August Patch Tuesday fix for CVE-2026-68820, a use-after-free race condition in AFD.sys, and flagged it as the only flaw in that release under active exploitation.
Show sources
- Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day — www.infosecurity-magazine.com — 12.08.2026 16:35
-
28.07.2026 03:00 2 articles · 29d ago
Check Point reports CVE-2026-68820 to Microsoft
Initial DisclosureCheck Point Research reported CVE-2026-68820, a use-after-free race condition in AFD.sys, to Microsoft after connecting it to Lazarus activity against defense and aerospace companies in Europe and India.
Show sources
- Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day — www.infosecurity-magazine.com — 12.08.2026 16:35
- Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day — www.infosecurity-magazine.com — 12.08.2026 16:35