Fast Facts
- Lazarus Group exploited a zero-day vulnerability in Windows (CVE-2026-68820) to deliver a sophisticated backdoor via DLL side-loading and trojanized PDF viewers, gaining full control of targeted systems.
- The campaign used legitimate websites and compromised infrastructure, including fake employer sites and cloud services, to mask malicious command-and-control communications and evade detection.
- Attackers hijacked trusted platforms like SharePoint and webmail servers vulnerable to specific exploits (e.g., CVE-2025-49113), deploying custom malware such as RelayShell for remote command execution in critical sectors worldwide.
Threat, Attack Techniques, and Targets
The Lazarus Group, a North Korean threat actor, used a new zero-day vulnerability in Windows called CVE-2026-68820. Microsoft had already patched this flaw. The vulnerability affects the Windows Ancillary Function Driver for WinSock (AFD.sys) and allows hackers to gain SYSTEM access.
The group uses social engineering to trick victims. They send fake recruiter messages and get targets to open malicious PDFs or install trojanized PDF viewers. Once installed, these tools connect to infrastructure controlled by the threat actors. They use two main infection methods:
1. DLL side-loading. Victims download an encrypted archive that triggers a malicious DLL (“libmupdf.dll”). This DLL displays a fake job description and downloads malware called MISTPEN. MISTPEN uses API calls and cloud services to retrieve other malware modules and exploit the AFD.sys flaw.
2. Trojanized “SecurityPDF” viewer. Victims are directed to fake websites impersonating Enveil to download this viewer. The viewer looks for a specific marker in PDFs. When it finds the marker, it decrypts and runs a backdoor called Troy directly in memory.
The campaign targets defense and aerospace companies across France, Germany, Brazil, and India. The attackers also use websites mimicking official vendors and hijacked legitimate sites for command-and-control.
Impact, Security Implications, and Remediation Guidance
The attack allows hackers to escalate privileges to SYSTEM level, bypass security measures, and maintain persistent access. They can fully control infected computers, steal sensitive data, and deploy remote access tools. The use of legitimate infrastructure and fake sites makes detection difficult.
Because the attackers exploit a recent zero-day vulnerability, organizations should first look to apply the official patches from Microsoft. If a patch is not yet available, or for additional protection, organizations should follow guidance from their security vendors and authorities.
Remediation measures include verifying software sources, avoiding clicking links in suspicious messages, and monitoring network traffic for unusual activity. Security teams should also inspect and patch vulnerabilities like CVE-2026-68820 and monitor for signs of DLL side-loading or malicious PDF viewer activity. For detailed guidance, organizations should consult their security vendors and the official Microsoft advisories.
Stay Ahead with the Latest Tech Trends
Dive deeper into the world of Cryptocurrency and its impact on global finance.
Access comprehensive resources on technology by visiting Wikipedia.
ThreatIntel-V1
