COLCERT warns on Operation Dream Job
COLCERT warned on Operation Dream Job and CVE-2026-68820, a Windows flaw used to raise privileges and deploy malware.
COLCERT issued alert COLCERT AL 20260820 114 on Operation Dream Job, a campaign attributed to Lazarus that abuses CVE-2026-68820 in Windows to elevate privileges to SYSTEM after initial execution on a device. The warning follows Microsoft’s August fix and CISA’s addition of the flaw to its catalog of actively exploited vulnerabilities.
COLCERT published alert COLCERT AL 20260820 114, titled "Operation Dream Job used to escalate privileges in Windows," amid reports tying the campaign to CVE-2026-68820, a Windows flaw used to raise privileges to SYSTEM level. Technical research attributes the activity to Lazarus, the North Korea-linked group, and describes attacks against defense, aerospace, and aviation sectors, with focus also on Europe, India, and Brazil.
What did COLCERT say?
COLCERT issued a specific alert to warn about Operation Dream Job being used as a path to privilege escalation in Windows. The Colombian agency published the notice on August 20, 2026, under the identifier COLCERT AL 20260820 114, in a context where the flaw had already been patched by Microsoft and was listed as actively exploited.
How does the exploited flaw work?
CVE-2026-68820 is a use-after-free in the Windows Ancillary Function Driver for WinSock, known as afd.sys. According to technical analyses, it allows local privilege escalation to SYSTEM once the attacker has code execution on the machine. Microsoft fixed the issue in its [August 2026](https://www.veracode.com/blog/application-risk-intelligence-august-19) Patch Tuesday, in a package of more than 398 vulnerabilities, and described it as a privilege escalation in afd.sys that was already being exploited when the patches were released.
What attack chain do the investigations describe?
Technical reports say the victim receives a compressed file containing a legitimate PDF viewer, a malicious DLL, and an encrypted PDF. After the initial execution, the attackers abuse CVE-2026-68820 to elevate privileges and deploy FudModule, a kernel rootkit designed to reduce the visibility of EDR tools. Check Point Research attributed that use of the vulnerability in Operation Dream Job to Lazarus.
How urgent is it to apply the patch?
CISA added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog on August 11, 2026, and set a remediation deadline of August 25, 2026, for U.S. federal civilian agencies. Several risk briefings placed the flaw among the main risks in the August 2026 patch cycle and recommended prioritizing its remediation on all Windows endpoints, strengthening rootkit detection, and hardening controls against fake recruiting campaigns on LinkedIn and corporate email.
Is there a workaround without patching?
No. The technical notes cited by Cloud Security Alliance say there are no effective workarounds for CVE-2026-68820. Mitigation depends on fully installing the August 2026 cumulative security updates for Windows and restarting affected systems.
What regional impact is mentioned?
International coverage of Operation Dream Job focuses on defense and aerospace organizations and their supply chains, as well as aviation companies and contractors in different countries. That scope suggests possible exposure for Colombian companies in those sectors, although no specific public cases in the country have been reported so far.
Microsoft, according to specialized coverage, did not attribute the exploitation of CVE-2026-68820 to Lazarus in its official communications. That link to Operation Dream Job comes from independent analysis by firms such as Check Point, not from the vendor.
Sources
- COLCERT AL – 20260820 - 114 Alerta: Operation Dream Job utilizada para escalar privilegios en Windowscolcert.gov.co· COLCERT
- Lazarus Windows Exploit Fuels New Espionage Campaigngreenbone.net· Greenbone
- Microsoft Patches 398 Flaws Including a Windows Driver Zero ...zerodayroom.com· Zerodayroom
- Lazarus Kernel Zero-Day Hits Defense Contractorslabs.cloudsecurityalliance.org· Cloud Security Alliance
- DPRK's Lazarus Group exploits Windows zero-day in ...scworld.com· SC World
- Issue #151 - InfoSec.Watchinfosec.watch· InfoSec.Watch
- Weekly Recap: VMware Exploits, Windows 0-Day, MCP ...thehackernews.com· The Hacker News
- CISO Application Risk Intel Briefing for Week of August 19veracode.com· Veracode
- Microsoft Patches Nearly 400 Flaws, Including Exploited afd.sys ...mallory.ai· Mallory.ai



