hacker-news · Crawled Aug 12, 2026

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

7 IoCs 1 Actors 4 Malware 1 CVEs
Read original article ↗

AI Summary

The North Korean threat actor Lazarus Group has exploited a Windows zero-day vulnerability, CVE-2026-68820, in the AFD.sys driver to escalate privileges to SYSTEM and deploy a new in-memory backdoor named Troy. The attack is part of Operation Dream Job, a long-running cyber espionage campaign using fake job offers on LinkedIn to lure victims into downloading trojanized software or opening malicious PDFs. Two infection chains were observed: one using DLL side-loading with the malicious libmupdf.dll and another via a trojanized SecurityPDF viewer that triggers payload execution upon detecting a specific marker in a PDF. The attackers also use compromised legitimate infrastructure, including WordPress, SharePoint, and vulnerable Roundcube servers (CVE-2025-49113), to host C2 communications and distribute the ForestTiger (ScoringMathTea) backdoor.

AI-extracted · verify before operational use

Extracted Entities 6 found

Indicators of Compromise 7 extracted

Type Value Detail
Domain envell[.]xyz Details →
Domain enveil[.]online Details →
Domain uxtramine[.]org Details →
Filename libmupdf.dll Details →
Filename Release_GetInfoPlugin_x64.dll Details →
Filename Release_PvPlugin_x64.dll Details →
Filename OneScreenCapture64.dll Details →

MITRE ATT&CK TTPs 45 techniques

T1003 OS Credential Dumping · Credential Access T1018 Remote System Discovery · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1021.004 SSH · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1029 Scheduled Transfer · Exfiltration T1040 Network Sniffing · Credential Access T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1070.001 Clear Windows Event Logs · Defense Evasion T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1085 T1085 T1087 Account Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1129 Shared Modules · Execution T1133 External Remote Services · Persistence T1134 Access Token Manipulation · Defense Evasion T1190 Exploit Public-Facing Application · Initial Access T1195.002 Compromise Software Supply Chain · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1218 System Binary Proxy Execution · Defense Evasion T1218.011 Rundll32 · Defense Evasion T1480 Execution Guardrails · Defense Evasion T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1495 Firmware Corruption · Impact T1534 Internal Spearphishing · Lateral Movement T1548 Abuse Elevation Control Mechanism · Privilege Escalation T1557 Adversary-in-the-Middle · Credential Access T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access T1566.002 Spearphishing Link · Initial Access T1583 Acquire Infrastructure · Resource Development T1610 Deploy Container · Defense Evasion T1087.002 Domain Account · Discovery