The job offer was the attack: a Windows zero-day delivered by fake recruiters
Lazarus used a Windows kernel zero-day, CVE-2026-68820, to blind endpoint security after luring defence engineers with fake job offers.
Researched and drafted with AI assistance, then reviewed and edited by Shreyas Lipare before publication. Every source below was checked against the original.
An engineer at a defence contractor gets a message from a recruiter. The role is a good fit. The company has a real website that ranks well in search. There is a document to read, and it needs a particular PDF viewer to open.
That is the whole trick. Everything after it, the backdoor, the kernel exploit, the rootkit that switches off the security tooling, follows from someone doing something entirely reasonable at work on a Tuesday.
Check Point Research published the analysis on August 11, 2026, the same day Microsoft patched the zero-day it relies on [1][2]. The actors had been using it since early July [1].
What happened
CVE-2026-68820 is a use-after-free in the Windows Ancillary Function Driver for
WinSock, AFD.sys, the kernel driver behind ordinary socket operations. NVD
rates it 7.0, local access, high attack complexity, low privileges required [2].
CISA added it to the Known Exploited Vulnerabilities catalog on August 11, 2026
[3].
The interesting part is what it was used for.
Check Point attributes the campaign to the DPRK-linked Lazarus group with high confidence, on the basis of malware families, infrastructure and tradecraft consistent with previously documented activity [1]. That is a vendor assessment made on stated grounds, not a government indictment, and Microsoft’s own advisory names no actor. Treat it as a well-supported analytic judgement rather than an established fact.
The campaign is Operation Dream Job, a long-running effort aimed at the defence sector: aerospace, aviation, surveillance sensors, drones and robotics, with activity concentrated in Western Europe, India and South America [1].
The route in is a fake recruiter. Targets are approached on professional networking platforms with an attractive opportunity and directed to download files. Check Point found three fake websites impersonating a real privacy technology company, some of which ranked as top search results for relevant queries [1]. An engineer who does the sensible thing, searches for the company before engaging, can land on the attacker’s site by doing so.
The timeline is worth keeping: exploitation active by early July, Microsoft notified on July 28, 2026, confirmed by Microsoft on July 31, CVE assigned on August 5, patch released on August 11 [1]. Roughly five weeks between the exploit being in use and a fix existing.
Why this matters
Three things generalise beyond this campaign.
The privilege escalation is the load-bearing step here. A 7.0 that requires local access looks unremarkable in a patch list of hundreds. But this class of flaw is what converts “code running as a user” into “code running as SYSTEM”, and SYSTEM is the privilege level at which you can start switching off the things that watch you. Rank privilege escalation flaws by what an attacker gains next, not by base score alone.
Your EDR is also a target. After escalating, the actors deployed a new version of FudModule, Lazarus’ kernel-mode rootkit. Check Point’s analysis describes it disabling security telemetry through process, thread and registry callbacks, removing minifilters, killing event tracing providers, suppressing crash dumps, and (new in this version) tampering with Smart App Control [1]. This is not evasion in the sense of avoiding a signature. It is turning the sensor off from underneath.
Which raises an operational question most teams have not answered: would you notice if a host simply stopped reporting? Most alerting is built on bad events arriving. Very little is built on expected events failing to arrive.
The lure targets a good instinct. Career opportunity is not a weakness to be trained out of people. Telling engineers to be suspicious of recruiters asks them to sacrifice something real for a threat they cannot assess, and it will not hold. The control that holds is procedural, and it belongs to IT rather than to the individual.
Technical breakdown
The chain, as described in Check Point’s analysis. It is set out here so you can recognise and interrupt it; the exploitation specifics are deliberately absent.
- ReconnaissanceIdentifies engineers at defence and aerospace firms and approaches them as a recruiter on a professional network
BREAK THE CHAIN HERE
Route all unsolicited recruiter attachments and downloads through a channel that is not the employee's work machine, a managed sandbox, a virtual desktop, or simply "open it on your phone". Detection: alert on first-seen executables written to user profile directories on engineering workstations. - Initial accessDirects the target to a convincing fake company site, several of which ranked highly in search results for the impersonated brand
- ExecutionThe target installs a trojanised PDF viewer built on a legitimate open-source rendering framework
BREAK THE CHAIN HERE
Application allowlisting, so an unsigned or unknown viewer cannot execute on a managed endpoint regardless of how convincing the pretext was. Detection: hunt for PDF readers running from user-writable paths, and for DLL sideloading by document-handling applications. - ExecutionOpening a specially crafted document causes the viewer to extract and run an embedded payload
- Command and controlA modular backdoor establishes redundant connectivity across several configured servers and awaits operator commands
- Privilege escalationExploits the AFD.sys use-after-free to win a race in kernel memory and reach SYSTEM
BREAK THE CHAIN HERE
Install the August 2026 Patch Tuesday updates. This is the only step in the chain that a patch closes, which is exactly why it should not be the only control you rely on. - Defence evasionLoads a kernel rootkit that removes filter drivers, kills event tracing providers and suppresses crash dumps, blinding endpoint tooling
BREAK THE CHAIN HERE
Alert on absence, a managed host whose EDR telemetry stops arriving, whose ETW providers go quiet, or whose crash reporting ceases. Detection: monitor sensor heartbeat and flag hosts silent beyond a threshold rather than waiting for a bad event. - ImpactOperates with SYSTEM privileges inside the target network with reduced defensive visibility
Four steps carry a break. Two of them are worth dwelling on.
Application allowlisting is the control that would have stopped this before the kernel was ever involved. The entire chain depends on a specific unsigned application running on a work machine. Everything downstream, the backdoor, the exploit, the rootkit, is unreachable if that first binary cannot execute. Allowlisting is unpopular because it is work, and this is the kind of intrusion that makes the case for it.
Alerting on absence is the harder one, and the more valuable. When the adversary’s mid-chain objective is to stop your telemetry, silence becomes a signal. Concretely: track EDR agent check-ins per host, alert when a host that normally reports goes quiet for longer than its baseline, and treat “the sensor stopped” as an incident rather than an IT ticket. Most organisations discover they cannot do this only when they need it.
On the exploit itself, the honest description is short. It is a use-after-free in the socket driver, triggered by a race between threads touching socket state concurrently, and winning that race yields kernel memory access [1][2]. The specifics of how the race is won are not reproduced here, and are not necessary for defence.
What defenders should do Monday morning
Immediate: today.
Deploy the August 2026 Patch Tuesday updates, prioritising engineering, research and executive workstations over servers. This is a client-side chain and the exposure is where people read documents [1][3]. Confirm coverage rather than assuming it, using whatever your patch tooling reports as actual install state.
Near term: this week.
Check that your EDR reports sensor health somewhere a human sees, and find out how long a host can be silent before anyone notices. If the answer is “we would not notice”, that is the finding. Hunt for PDF readers and document handlers executing from user-writable directories, and for document applications sideloading DLLs [1].
Talk to whoever runs recruitment-adjacent communication in your organisation and establish one rule: files from unsolicited recruiters are not opened on corporate endpoints. Give people a supported alternative rather than a prohibition.
Structural: this quarter.
Move toward application allowlisting on engineering endpoints, even in audit mode first. Baseline EDR telemetry volume per host so absence is measurable. Review whether your defence-sector suppliers and contractors have the same controls, since this campaign targets the sector rather than one company.
Checklist
- Install August 2026 Patch Tuesday updates; verify install state, don’t assume.
- Prioritise engineering and research workstations over servers.
- Confirm someone sees EDR sensor-health data daily.
- Alert when a managed host’s telemetry stops arriving.
- Hunt for document readers executing from user-writable paths.
- Hunt for DLL sideloading by PDF and document applications.
- Set a rule that recruiter files are never opened on corporate endpoints.
- Pilot application allowlisting on engineering endpoints in audit mode.
- Ask key suppliers whether they have patched this.
What this campaign is really exploiting
Not AFD.sys. The driver flaw is five weeks of a much longer operation, and
Microsoft has closed it.
What the campaign exploits is that ambitious engineers answer recruiters, that searching for a company before engaging feels like diligence, and that security tooling is assumed to be watching right up until the moment it is not. Each of those is a reasonable behaviour or a reasonable assumption, and the attack is built out of them rather than around them.
The patch closes one step. The parts that would have broken the chain earlier controlling what can execute, and noticing when your visibility disappears are the same two things they were before this zero-day existed, and they will still be the answer for the next one.
FREQUENTLY ASKED
- It needs local access and scores 7.0. Why does that matter?
- Because it is not the way in. It is the second step. The actor already has code running as a normal user from the trojanised application. This flaw turns that foothold into SYSTEM, and SYSTEM is what lets them load a kernel rootkit and switch off the tooling that would have caught them. A low base score on a privilege escalation flaw hides how load-bearing it is in a real chain.
- Our EDR did not alert. Does that mean we were not hit?
- Not necessarily, and that is the uncomfortable part. The rootkit deployed after this exploit is designed to disable security telemetry: kernel callbacks, event tracing providers, filter drivers. A quiet console can mean nothing happened, or it can mean the sensor stopped reporting. Alert on telemetry that stops arriving, not just on telemetry that looks bad.
- Who is actually being targeted?
- Check Point describes a focus on the defence sector globally, with emphasis on aerospace, aviation, surveillance sensors, drones and robotics, and activity concentrated in Western Europe, India and South America. If you are not in that population your urgency is lower, but the patch is the same patch, and the lure works on anyone.
- Is telling staff to be suspicious of recruiters realistic?
- On its own, no. Job offers are a legitimate and welcome part of professional life, and asking engineers to distrust them is asking them to give something up. The practical control is not suspicion, it is process: nothing from a recruiter gets run on a work machine, and anything requiring a special viewer is verified out of band first.
REFERENCES
- [1]Shattering the Dream, When a Job Offer Becomes a Zero-Day AttackVENDOR RESEARCH
- [2]CVE-2026-68820 DetailPRIMARY
- [3]Known Exploited Vulnerabilities Catalog (JSON feed)PRIMARY
BEFORE YOU GO
Was this useful?
Tell me what you'd change, what was unclear, or what you'd want covered next. Replies shape what gets written.
SEND FEEDBACK ↗