logo

Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day

ID: 0a852931-5067-57cf-abc6-a5de1808cbc8

STIX ID: report--0a852931-5067-57cf-abc6-a5de1808cbc8

Feed Name: Infosecurity Magazine (News)

Threat Score
92/100

Date Published: 2026-08-12

Date Updated: 2026-08-12

...
...

Check Point Research disclosed that North Korea’s Lazarus group ran an active campaign (Operation Dream Job) targeting defense and aerospace organizations across Europe, India and Brazil, exploiting a Windows kernel zero-day (CVE-2026-68820) to deliver an in-memory downloader (MISTPEN) which negotiated a Kyber post-quantum key exchange and fetched a kernel rootkit (FudModule v3.1); operators relied on compromised Roundcube/PrestaShop servers hosting a RelayShell PHP relay, trojanized vendor-impersonating sites, and delivered a new backdoor called Troy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.