Lazarus Group Exploits New Windows Zero-Day to Deploy FudModule Rootkit Against Defense Targets
Check Point Research reported that DPRK-linked Lazarus Group targeted defense, aerospace, and aviation firms in Europe, India, and Brazil, with confirmed compromises in France and Germany, in a new wave of its Operation Dream Job campaign
Check Point identifies a third-generation Lazarus loader embedding the AFD.sys exploit in a modular framework, MISTPEN, that retains reconnaissance and LPE plug-in capability, so Microsoft's August 11 patch closes one entry point without addressing the delivery architecture. The Troy backdoor and RelayShell webshell extend the group's infrastructure onto compromised Roundcube and WordPress servers, giving it relay capacity independent of any single vulnerability, though the CVE's inclusion in CISA's KEV catalog and the patch suggest the disclosure now functions mainly as retrospective attribution rather than an active unpatched threat window. Findings rest on a single primary source, Check Point, with only secondary amplification elsewhere. Defense, aerospace, and aviation organizations contacted via Dream Job-style recruiting before August 11 should treat FudModule, ForestTiger, or Troy indicators as evidence of prior SYSTEM-level compromise regardless of current patch status.
4 sources
- Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack -
Check Point Research - Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor -
The Hacker News - Lazarus hackers exploited Windows zero-day to target defense firms -
BleepingComputer - Lazarus Group Exploits Windows Zero-Day in Backdoor Campaign - DPRK Cyber Threat -
News4Hackers