LIVE · cybersecurity feed
Live wire
malware

Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day

Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit

zeroday.news ·

The North Korean-backed Lazarus Group has been observed deploying a Windows zero-day exploit, CVE-2026-68820, using a command channel secured with a post-quantum key exchange mechanism. This activity is part of the ongoing "Operation Dream Job" campaign, which targets employees at defense and aerospace companies in Europe and India with fraudulent job offers.

The vulnerability, a use-after-free race condition in the `AFD.sys` driver, which handles network sockets in the Windows kernel, was reported to Microsoft on July 28 and subsequently patched on August 11. Microsoft confirmed that this was the only flaw in its August Patch Tuesday release that was under active exploitation.

The attack chain begins with an in-memory downloader named MISTPEN, which communicates via attacker-controlled files on OneDrive using the Microsoft Graph API. After initial reconnaissance and establishing persistence, MISTPEN loads a dedicated module to fetch the privilege escalation exploit. This module first fingerprints the victim's host, then requests four public keys from the command server. It utilizes these keys to generate new key material with Kyber/ML-KEM, a key encapsulation scheme standardized by NIST in 2024 for its resistance to quantum computer attacks. The encapsulated result is then returned to the server before the exploit itself is requested, decrypted, and executed in memory.

The command channel traffic is secured with multiple layers of encryption. In addition to MISTPEN's AES transport encryption, a second layer using GOST-CBC is applied, followed by the post-quantum key exchange. The exploit delivered through this handshake is FudModule, Lazarus's kernel rootkit, specifically version 3.1. This rootkit is designed to disable telemetry callbacks, remove minifilters, terminate the NT Kernel Logger, and blind 94 Event Tracing for Windows (ETW) providers. A newly identified capability of FudModule is its ability to tamper with Smart App Control, resetting its policy state and forcing a code integrity reload.

Lazarus Group's infrastructure for this campaign relies heavily on compromised third-party servers. They have utilized Roundcube webmail servers, likely exploited via CVE-2025-49113 using credentials obtained from dark web leaks, as well as compromised PrestaShop sites. These servers host RelayShell, a previously undocumented PHP webshell that functions as a message relay between the operator and victim through session files, rather than a conventional command shell. Evidence suggests at least 17 such relay servers have been compromised.

The initial delivery methods have also evolved. The group created at least three websites impersonating the privacy technology vendor Enveil, some of which ranked highly in search results. It is important to note that Enveil was neither targeted nor compromised in this operation. These deceptive websites distributed a trojanized PDF viewer containing a payload hidden within crafted documents. This payload delivers Troy, a previously undocumented backdoor that supports 17 operator commands. The targeting for Operation Dream Job has included organizations involved in surveillance sensors, drones, and robotics, with observed activity or targeting in France, Germany, Brazil, and India.

malwarezero-day
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.

vulnerability

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.

CVE-2026-58231critical

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.

vulnerability

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klonen.” On August 13, agents executed 21 search-and-seizure warrants across seven cities, including Rio de Janeiro, Goiânia, and