PUBLIC DOSSIER · CYBERESPIONAGE · 13 AUGUST 2026Status: current as of this date

The page’s question: what does “trusted” mean when every link can be authentic and still be used by someone else?

Everything looked legitimate

In the new Operation Dream Job wave, a familiar name, signed software, a Microsoft service and a compromised organisation could all belong to the same malicious story. The lesson is relational: an authentic thing does not authenticate the chain that carries it.

Choose a link. Read what was real and what was abused.

“Real” describes a thing. “Safe” describes its relationship with the rest of the chain.
CVE 2026-68820 Windows zero-day, patched 11 August
17+ servers identifiers for likely compromised relays
FR · DE observed activity organisations involved in the published research
11 Aug. 2026 Microsoft patch and CISA KEV listing
Choose a link. Read what was real and what was abused.REAL ≠ SAFE

Evidence that holds the chain in place

Exploitation CONFIRMED

Microsoft and CISA support the vulnerability status.

DPRK attribution ASSESSMENT

The attribution belongs to Check Point’s analysis.

French victim OBSERVED

The organisation is not named publicly.

Stolen impact UNKNOWN

The research does not list exfiltrated information.

The new signal

Trust became reusable

Fake job offers from the Lazarus ecosystem are familiar. The new feature in this reconstruction is the combination: recruitment, genuine software, search visibility, OneDrive, a kernel zero-day, compromised web servers and a victim used for the next round.

For a defender, that changes the question. A familiar domain, a valid signature or a mainstream cloud service describe an object. They do not automatically verify the relationship between that object and the message that brings it into a network.

“Real” describes a thing. “Safe” describes its relationship with the rest of the chain.

01 · What happened

The offer became access, then infrastructure

Before reading the signals, here is the four-moment operational reconstruction. It follows the primary source’s described sequence; it is not a complete list of victims or impact.

01IMPERSONATED

The lure looked professional

A recruiter and a familiar employer name opened the conversation.

Check Point
02REAL

The program looked legitimate

A signed PDF viewer and OneDrive made the installation and traffic look ordinary.

Check Point
03MALICIOUS

The zero-day raised privileges

CVE-2026-68820 in Windows AFD.sys opened the route to SYSTEM.

CISA
04COMPROMISED

The victim became infrastructure

Compromised web servers and the reputation of an organisation in France were reused for traffic and later messages.

Check Point

02 · The signals

A chain of real things can deliver a false intention

Each row carries a signal that a reader or a system might recognise. Open it to see the signal’s limit.

The campaign’s trust chain
Status
01 IMPERSONATED

Employer name

A realistic listing used the Lockheed Martin name.
Why it matters

The name was familiar. The published research does not indicate company involvement in the campaign. Open source: Check Point Research

02 IMPERSONATED

Offer and recruiter

The approach arrived as a plausible professional opportunity.
Why it matters

Professional identity is easy to borrow when a target expects a job offer or a technical conversation. Open source: Check Point Research

03 REAL

Digitally signed PDF viewer

A signed program made the installation look ordinary.
Why it matters

An authentic signature attests to a file’s origin, not to the intent of the person placing it in the chain. Open source: Check Point Research

04 IMPERSONATED

Search result

Pages impersonating Enveil appeared high in relevant results.
Why it matters

Search visibility supplied a second legitimacy signal. Open source: Check Point Research

05 REAL

Microsoft OneDrive

OneDrive appeared in the malware’s communications.
Why it matters

A real service can carry traffic with a malicious purpose. Open source: Check Point Research

06 REAL

Windows AFD.sys

CVE-2026-68820 opened the route to SYSTEM privileges.
Why it matters

Microsoft patched the vulnerability on 11 August 2026. CISA listed it as actively exploited. Open source: CISA · Known Exploited Vulnerabilities

07 COMPROMISED

European organisation

An organisation headquartered in France was later used as a sender.
Why it matters

The organisation is not named publicly. Its reputation became an operational asset for later messages. Open source: Check Point Research

08 COMPROMISED

Ordinary web server

Roundcube and CMS servers were used as relays.
Why it matters

Check Point identified at least 17 identifiers corresponding to likely compromised servers. Open source: Check Point Research

09 MALICIOUS

Troy, FudModule, RelayShell

The components delivered access, concealment and relay.
Why it matters

The investigation describes Troy, FudModule v3.1 and RelayShell as parts of the attack architecture. Open source: Check Point Research

REAL

genuine in itself, while still usable in a malicious relationship

IMPERSONATED

an identity, page or context imitates a familiar signal

COMPROMISED

a legitimate resource was taken over and used by someone else

MALICIOUS

the component or action belongs to the attack chain

03 · Escalation

Recruitment opened a route to the kernel

The technical path becomes legible when the social opening remains in the same timeline as the system-level outcome.

CVE-2026-68820 is confirmed as actively exploited. The link to Lazarus for this wave remains Check Point’s assessment.

Check Point reports the bug

Researchers send the vulnerability to Microsoft.

CHECKPOINT

Microsoft confirms the vulnerability

The issue enters the coordinated patch process.

MICROSOFT

It receives a CVE

The vulnerability becomes CVE-2026-68820.

MICROSOFT

Patch and KEV listing

Microsoft publishes the fix and CISA adds it to Known Exploited Vulnerabilities.

CISA

Independent reporting

The Record separates confirmed exploitation from Check Point’s attribution.

RECORD

04 · Victim as infrastructure

A compromised organisation became a resource for the next target

Check Point describes two forms of reuse. Legitimate web servers carried implant communications, while an organisation headquartered in France was later used for spear-phishing. Choose the route you want to follow.

Choose the highlighted route

Traffic passes through a compromised legitimate server and resembles ordinary HTTPS.

COMPROMISED

Legitimate organisation

compromised in France

infrastructure
COMPROMISED

Compromised web server

Roundcube / CMS + RelayShell

MALICIOUS

Implant communications

pass through ordinary infrastructure

reputation
IMPERSONATED

Reputation used as sender

the victim’s name raises message credibility

MALICIOUS

Target organisations

spear-phishing toward later targets worldwide

Read the reconstruction · Check Point Research

05 · What we know

Facts, assessment and unknowns do not carry the same weight

The page keeps separate what the sources document, the actor assessment, the inference about technical continuity and what the research does not publish.

ACTOR ASSESSMENT

Check Point attributes this wave to the Lazarus / DPRK ecosystem. Public Microsoft and CISA materials confirm the vulnerability and exploitation without making that attribution themselves.

Open source: Check Point Research
INFERENCE

The fact that FudModule previously used a vulnerability in the same AFD.sys driver suggests sustained technical knowledge. That is an interpretation, not evidence of who discovered each bug.

Open source: Check Point Research
UNKNOWN

The research does not say what defence information was exfiltrated from each victim, who consumed it or whether the operation concretely changed a weapons programme.

Open source: Check Point Research

The Romanian question

Defence-technology suppliers enter the same question

The public material does not disclose a Romanian victim. The research question is still clear: Romanian suppliers of drones, surveillance sensors, robotics and aerospace technology sit in the same technology categories named in the campaign analysis. This is an inference about exposure, not a report of a compromise.

The target categories come from Check Point’s analysis ↗
INFERENCE · NO ROMANIAN VICTIM DISCLOSED

What travels beyond the page

Check the relationship, not only the emblem

When a message looks legitimate, three questions are useful:

  1. Who controls the channel through which the request arrived?
  2. Which part of the relationship was independently verified?
  3. What changes if the sender itself has been compromised?

In this campaign, the answer to the third question was the infrastructure of the next target.

Sources and limits

A citable dossier with attribution kept in its place

Check Point provides the main technical reconstruction. CISA and Microsoft support the public vulnerability record. The Record helps separate confirmed exploitation from the actor attribution.

01PRIMARY SOURCE

Check Point Research

The campaign, malware, relay servers and French victim reuse reconstruction.

Open source ↗
02INDEPENDENT CONFIRMATION

CISA · Known Exploited Vulnerabilities

CVE-2026-68820 listed as actively exploited.

Open source ↗
03OFFICIAL RECORD

Microsoft Security Update Guide

The vulnerability record and Microsoft patch context.

Open source ↗
04SECONDARY REPORTING

The Record from Recorded Future News

Patch and exploitation separated from Check Point’s DPRK attribution.

Open source ↗

Temporal status

Current as of 13 August 2026. Re-review if primary sources change the description of exploitation, the CVE-2026-68820 status, the attribution or the limits around victim impact.