Security.io Intelligence DeskThursday, 3 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Threat Intelligence · Executive briefing

Lazarus campaign used a Windows zero-day to suppress endpoint visibility

Check Point linked active exploitation of CVE-2026-68820 to a Lazarus campaign using fake recruitment, trojanised PDF software, kernel-level EDR suppression and compromised webmail infrastructure.

Threat IntelligenceEndpoint SecurityVulnerability Management
Why it is in today’s brief

The patch was released before the core publication window, but fresh reporting exposed the enterprise-significant context: targeted zero-day use, EDR suppression, new malware and compromised webmail relays. This warrants inclusion because it changes prioritisation from routine Windows deployment to a campaign-specific hunt and compromise assessment, particularly for defence-linked organisations, without consuming a second vulnerability-category slot.

Read first

Prioritise CVE-2026-68820 where targeted personnel or suspicious PDF delivery create a plausible foothold. The August Windows update closes the privilege-escalation route, but evidence-based closure requires hunts for the delivery chain, EDR impairment and abused web infrastructure.

Act now

Deploy the August Windows updates to endpoints supporting defence, aerospace and aviation personnel.

Accountable owner

Threat Intelligence Lead, supported by Endpoint Engineering and Incident Response

Decision horizon

Immediate for defence-linked organisations; patch and hunt across exposed business units within 24 hours.

AssessmentHigh confidence
Emerging riskWatch for independent government attribution, additional affected Windows builds, named victims, new RelayShell infrastructure or activity outside the currently reported sectors and regions.

What happened

Check Point Research reported the vulnerability to Microsoft on 28 July 2026; Microsoft confirmed it three days later, assigned CVE-2026-68820 on 5 August and released the fix on 11 August 2026. Microsoft describes CVE-2026-68820 as a local use-after-free in the Windows Ancillary Function Driver for WinSock that can yield SYSTEM privileges without user interaction after local authentication. Check Point says the observed exploit specifically supported Windows 11 builds 26100 and 26200.

Check Point says it tracked the campaign from early 2026 and that exploitation of CVE-2026-68820 was occurring by early July 2026. The two delivery paths used an encrypted archive with a signed PDF viewer and malicious DLL, or a trojanised SecurityPDF viewer that loaded the Troy backdoor from a crafted PDF. After privilege escalation, the campaign deployed FudModule v3.1 to interfere with EDR telemetry and Windows security controls.

Troy supports 17 operator commands, while RelayShell used compromised Roundcube and content-management servers as relays. MISTPEN communicated through Microsoft Graph and OneDrive before deploying the ForestTiger backdoor in one chain. The Check Point summary page did not publish file hashes or domains in its body; it directed readers to the full research publication for indicators. Attribution posture: Check Point Research attributes the campaign to the North Korea-affiliated Lazarus group.

Why this matters now

The local privilege-escalation rating understates the observed enterprise consequence. The attacker first establishes user-context execution through targeted recruitment lures, then uses CVE-2026-68820 to obtain SYSTEM privileges and suppress endpoint visibility. A severity-only queue could place the flaw behind unauthenticated critical vulnerabilities even though it is already embedded in an espionage operation against sensitive organisations.

The campaign also creates two exposure roles. Employees can be direct targets through malicious recruitment content, while organisations running compromised Roundcube or content-management infrastructure can become relays that lend trusted reputation and normal-looking web traffic to the operation. Patch management, endpoint hunting and external-service assurance therefore need one coordinated decision.

The decision for security leaders

Prioritise by campaign plausibility, not CVSS alone. Systems used by recruited engineers, programme staff and other sensitive personnel require the shortest deployment and hunt window.

Separate update completion from compromise closure. CVE-2026-68820 is a post-entry escalation mechanism, so a patched endpoint may still contain malware delivered before remediation.

Assign external-service owners to determine whether webmail or content-management infrastructure could be operating as attacker relay capacity, even when the organisation was not the intended espionage target.

Evidence of closure

  • Deployment records confirm applicable Windows security updates and successful post-update restarts.
  • Hunt results document no matching delivery, malware or defence-impairment behaviours across the review window.
  • Sensitive-user mail and endpoint cases have approved dispositions for relevant recruitment approaches.
  • Roundcube and content-management owners provide documented patch and credential-assurance results.

The Security.io assessment

Active exploitation of CVE-2026-68820 is confirmed by Microsoft, while the detailed campaign and actor assessment comes from Check Point Research. Attribution posture: Check Point Research attributes the campaign to the North Korea-affiliated Lazarus group. Independent government attribution for this specific activity was not present in the selected sources.

The campaign combines recurring recruitment tradecraft with materially new exploit and malware details. The Check Point summary page did not publish file hashes or domains in its body; it directed readers to the full research publication for indicators. Defenders should therefore retain behavioural hunts and not reduce closure to a hash search.

Security.io assesses the principal enterprise risk as targeted espionage with defence evasion, not opportunistic mass exploitation. Our assessment changes if authoritative telemetry shows broad commodity use, additional affected builds or exploitation outside the reported targeting pattern.

Questions for the morning meeting

  • Have high-risk staff received recruitment approaches involving PDF viewers, encrypted archives or software downloads?
  • Can the SOC distinguish successful patching from evidence that FudModule or related malware never executed?
  • Are public Roundcube and content-management systems assessed for both known flaws and leaked credentials?

Related intelligence

Shared decision context