Ethical Hacking News
The Lazarus Group has exploited a previously patched Windows zero-day vulnerability to gain SYSTEM access and deploy a never-before-seen backdoor, highlighting the ongoing threat posed by nation-state actors seeking to compromise critical infrastructure and steal sensitive information. The attack demonstrates a high level of sophistication, making it challenging for users to detect and prevent such attacks.
The Lazarus Group has exploited a previously patched Windows zero-day vulnerability (CVE-2026-68820) to gain SYSTEM access and deploy a never-before-seen backdoor. The attackers employed a sophisticated attack chain involving a trojanized PDF viewer, dubbed SecurityPDF, to deliver the payload. The Troy backdoor provides remote access to compromised machines and allows attackers to bypass security controls. The attackers used a DLL side-loading mechanism to stealthily download and execute malicious code. At least three websites impersonating Enveil were created to distribute the SecurityPDF viewer as part of the social engineering campaign. The attackers hijacked compromised websites and webmail servers to use as command-and-control (C2) servers, making it difficult to distinguish this campaign from normal traffic. Experts emphasize the importance of patching updates in a timely manner, verifying software through official channels, and extending zero-trust thinking to legitimate-looking sites and partners.
The Lazarus Group, a notorious North Korean threat actor known for its sophisticated cyber espionage tactics, has recently exploited a previously patched Windows zero-day vulnerability to gain SYSTEM access and deploy a never-before-seen backdoor. This latest attack highlights the ongoing threat posed by nation-state actors seeking to compromise critical infrastructure and steal sensitive information.
According to recent findings by Check Point Research, the Lazarus Group has been attributed to the exploitation of CVE-2026-68820, a local privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys"). This vulnerability, which was patched by Microsoft as part of its Patch Tuesday updates in August 2026, provides an entry point for the threat actors to inject malicious code into the operating system and gain SYSTEM privileges.
The attackers have employed a sophisticated attack chain that involves the use of a trojanized PDF viewer, dubbed SecurityPDF, to deliver the payload. The SecurityPDF viewer is designed to appear legitimate and trustworthy, making it difficult for users to detect as phishing. Once installed, the viewer monitors for any PDF document opened through it for a special marker, which triggers the launch of an embedded payload that loads a backdoor called Troy directly into memory.
The Troy backdoor provides remote access to the compromised machine and allows the attackers to bypass security controls. The attack chain also employs a DLL side-loading mechanism, in which victims are instructed to download an encrypted archive that is used to trigger a DLL side-loading chain. This mechanism allows the threat actors to stealthily download and execute a lightweight downloader dubbed MISTPEN, which communicates with threat actor-controlled infrastructure using Microsoft Graph API and OneDrive to retrieve and run reconnaissance and persistence modules.
The attackers have also created at least three websites impersonating Enveil to distribute the SecurityPDF viewer, although it is unclear how these fake portals were incorporated into the social engineering campaign. The domains listed below are envell[.]xyz, enveil[.]online, and uxtramine[.]org.
Furthermore, the attackers have hijacked legitimate but compromised WordPress and SharePoint websites and vulnerable Roundcube webmail servers for use as ForestTiger command-and-control (C2) servers, making it challenging to differentiate this campaign from normal web traffic. Many of these Roundcube servers have been found to be vulnerable to CVE-2025-49113, which the attackers leverage to infect them with a previously undocumented PHP web shell codenamed RelayShell.
Sergey Shykevich, director of threat intelligence at Check Point Software, has stated that "what makes this campaign so dangerous is not only the zero-day vulnerability but also how Lazarus wove legitimate, trusted infrastructure into every stage of the attack." He noted that the attackers hid in plain sight, behind top-ranked search results, real vendor branding, and the reputation of organizations they had already compromised. Shykevich emphasized the importance of patching moment updates land, verifying software through official channels rather than search rankings, and extending zero-trust thinking to legitimate-looking sites and partners we interact with every day.
In conclusion, this attack highlights the ongoing threat posed by nation-state actors seeking to compromise critical infrastructure and steal sensitive information. The Lazarus Group's sophisticated tactics demonstrate a high level of sophistication, making it challenging for users to detect and prevent such attacks. It is essential that users take proactive measures to protect themselves from these types of threats.
The Lazarus Group has exploited a previously patched Windows zero-day vulnerability to gain SYSTEM access and deploy a never-before-seen backdoor, highlighting the ongoing threat posed by nation-state actors seeking to compromise critical infrastructure and steal sensitive information. The attack demonstrates a high level of sophistication, making it challenging for users to detect and prevent such attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/Lazarus-Group-Exploits-Windows-Zero-Day-Vulnerability-to-Deploy-Sophisticated-Backdoor-ehn.shtml
https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html
https://nvd.nist.gov/vuln/detail/CVE-2025-49113
https://www.cvedetails.com/cve/CVE-2025-49113/
https://nvd.nist.gov/vuln/detail/CVE-2026-68820
https://www.cvedetails.com/cve/CVE-2026-68820/
Published: Wed Aug 12 13:45:31 2026 by llama3.2 3B Q4_K_M