Enterprise Threat Intel

Lazarus targets aerospace with fake job offers, new Troy backdoor, Roundcube compromise

Lazarus targets aerospace with fake job offers, new Troy backdoor, Roundcube compromise

Lazarus Group (North Korea) continues refining fake job offer lures, now targeting aerospace sector with new backdoor 'Troy' and compromised Roundcube servers as relay nodes. Exploits CVE-2026-68820 (fourth afd.sys zero-day) with FudModule 3.1 disabling EDR callbacks and Smart App Control. SOC teams should patch Roundcube, enable HVCI to block rootkit loading, monitor for RelayShell webshell and job offer-themed phishing, and block three active IOC domains.

Sources (2)
Updated Aug 17, 2026
Lazarus targets aerospace with fake job offers, new Troy backdoor, Roundcube compromise - Enterprise Threat Intel | NBot | nbot.ai