2026-08-12HIGHexploitedCheck Point ties Operation Dream Job's 2026 wave to an exploited kernel zero-day patched on 11 August, with confirmed compromises in France and Germany
Roundcube Crypt_GPG_Engine PHP deserialization RCE - chained by UNK_MassTraction after CVE-2024-42009 XSS (Proofpoint)
cve · CVE-2025-49113 single-source
Coverage
2
first 2026-07-09 → last 2026-08-28
Latest activity
2026-08-12
Check Point ties Operation Dream Job's 2026 wave to an exploited kernel zero-day patched on 11 August, with…
Peak priority
high
1 high · 1 notable
Targets
public-sector
sectors: public-sector, technology, defense · regions: europe, us
Sources cited
5
5 hosts
Action items (4)
Do-now tasks recorded on the entries about CVE-2025-49113, newest first. Check the date before acting on an older one.
- Deploy the August 2026 Windows cumulative update to every Windows 11 24H2/25H2 endpoint that handles externally-sourced documents; CVE-2026-68820 is the exploited step that turns a user-level foothold into SYSTEM and removes endpoint visibility.2026-08-12CVE-2026-68820 +1
- Check every internet-facing Roundcube instance against the vendor's 2025 advisory for CVE-2025-49113 and treat any unpatched hit as a candidate C2 relay node rather than only a mail-data exposure, look for unexpected PHP files in the web root and repeated small POSTs to plausible-looking static-asset paths.2026-08-12CVE-2026-68820 +1
- Verify every Roundcube instance (especially research/education and public-sector webmail) is patched against CVE-2024-42009 and CVE-2025-49113, and treat unpatched webmail as an internet-facing edge device on par with a VPN concentrator.2026-07-09CVE-2024-42009 +1
- Hunt the post-exploitation chain on Roundcube servers: unexpected PHP-upload-handler deserialization activity, webshell files planted in plugin directories (timestomped to match legitimate plugins), and Roundcube session termination bursts that force user logout and clear forensic state.2026-07-09CVE-2024-42009 +1
Defender insights
What each entry about CVE-2025-49113 tells a defender to do, newest first.
Triage
Triage
Story timeline
- 2026-08-12Lazarus burned a Windows AFD.sys zero-day (CVE-2026-68820) on European defence targets, FudModule v3.1 blinds the endpoint, and the C2 is other people's Roundcube and WordPress servers
- 2026-07-09UNK_MassTraction: suspected China-aligned actor exploits Roundcube as an edge device, chaining CVE-2024-42009 XSS into CVE-2025-49113 deserialization
Hunting pivots
Affected products
ATT&CK techniques (20 across 10 tactics)
20 techniques observed across 2 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Resource DevelopmentStage Capabilities: SEO Poisoning
- Initial AccessExploit Public-Facing Application · Phishing · Phishing: Spearphishing via Service
- ExecutionExploitation for Client Execution · User Execution: Malicious File · Hijack Execution Flow: DLL
- PersistenceServer Software Component: Web Shell
- Privilege EscalationProcess Injection · Exploitation for Privilege Escalation
- StealthRootkit · Obfuscated Files or Information: Embedded Payloads · Process Injection · Deobfuscate/Decode Files or Information · Hijack Execution Flow: DLL · Reflective Code Loading
- Defense ImpairmentDisable or Modify Tools
- DiscoveryProcess Discovery · System Information Discovery
- CollectionScreen Capture
- Command and ControlWeb Service: Bidirectional Communication · Ingress Tool Transfer
Resource Development TA0042
T1608.006Stage Capabilities: SEO Poisoning×1
Adversaries may poison mechanisms that influence search engine optimization (SEO) to further lure staged capabilities towards potential victims. Search engines typically display results to users based on purchased ads as well as the site’s ranking/score/reputation calculated by their web crawlers and algorithms.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
Initial Access TA0001
T1190Exploit Public-Facing Application×2
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · 2026-07-09/unk-masstraction-roundcube-edge-exploitation · ATT&CK page ↗
T1566Phishing×1
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-07-09/unk-masstraction-roundcube-edge-exploitation · ATT&CK page ↗
T1566.003Phishing: Spearphishing via Service×1
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
Execution TA0002
T1203Exploitation for Client Execution×1
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.
Evidence: 2026-07-09/unk-masstraction-roundcube-edge-exploitation · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×2
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · 2026-07-09/unk-masstraction-roundcube-edge-exploitation · ATT&CK page ↗
Privilege Escalation TA0004
T1055Process Injection×1
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
Stealth TA0005
T1014Rootkit×1
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
T1027.009Obfuscated Files or Information: Embedded Payloads×1
Adversaries may embed payloads within other files to conceal malicious content from defenses. Otherwise seemingly benign files (such as scripts and executables) may be abused to carry and obfuscate malicious payloads and content. In some cases, embedded payloads may also enable adversaries to Subvert Trust Controls by not impacting execution controls such as digital signatures and notarization tickets.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
T1055Process Injection×1
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
T1140Deobfuscate/Decode Files or Information×1
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
T1620Reflective Code Loading×2
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · 2026-07-09/unk-masstraction-roundcube-edge-exploitation · ATT&CK page ↗
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
Discovery TA0007
T1057Process Discovery×1
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
T1082System Information Discovery×1
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
Collection TA0009
T1113Screen Capture×1
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
Command and Control TA0011
T1102.002Web Service: Bidirectional Communication×1
Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule · ATT&CK page ↗
Entries about Roundcube Crypt_GPG_Engine PHP deserialization RCE - chained by UNK_MassTraction after CVE-2024-42009 XSS (Proofpoint) (2)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Roundcube Webmail×2
- ForestTiger×1
- FudModule×1
- IceCube×1
- Lazarus Group×1
- Microsoft Windows×1
- Microsoft Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free race condition, exploited as a zero-day by the Lazarus-affiliated Operation Dream Job campaign to reach SYSTEM and load the FudModule v3.1 kernel rootkit; patched 2026-08-11, CISA KEV the same day.×1
- MISTPEN×1
Where this entity is cited
Source distribution
- cisa.gov1 (20%)
- msrc.microsoft.com1 (20%)
- proofpoint.com1 (20%)
- rapid7.com1 (20%)
- research.checkpoint.com1 (20%)
External references
All cited sources (5)
- proofpoint.comprimaryProofpoint Threat Researchhttps://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation
- cisa.govCISAhttps://www.cisa.gov/news-events/alerts/2026/08/11/cisa-adds-three-known-exploited-vulnerabilities-catalog
- msrc.microsoft.comMicrosoft Security Response Centerhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820
- rapid7.comRapid7https://www.rapid7.com/blog/post/em-patch-tuesday-august-2026/
- research.checkpoint.comCheck Point Researchhttps://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/