Lazarus hackers exploited Windows zero-day to target defense firms

North Korean Hackers Exploit Windows Zero-Day Vulnerability to Target Defense Firms

In a brazen attack, North Korea’s Lazarus threat group has been exploiting a previously unknown vulnerability in Microsoft Windows to infiltrate defense-sector companies across Europe and India. The hackers have been using the flaw, known as CVE-2026-68820, as part of their long-running Operation Dream Job campaign, which has been targeting military technology firms with sophisticated social engineering tactics.

The vulnerability itself is a “use-after-free” bug in the Windows Ancillary Function Driver for WinSock (AFD.sys), allowing an attacker to elevate their privileges and gain SYSTEM access without any user interaction. Microsoft patched the flaw in this month’s Patch Tuesday security updates, but Lazarus was able to exploit it before the fix was available. The hackers have been using a specially crafted application to trigger a race condition on affected systems, ultimately granting them full control.

Researchers at cybersecurity firm Check Point have been tracking the latest variant of Operation Dream Job and discovered that Lazarus has incorporated an exploit for CVE-2026-68820 into their FudModule kernel-mode rootkit. The new version of the rootkit not only elevates privileges but also adds capabilities such as disabling Endpoint Detection and Response (EDR) telemetry, interfering with security products, and tampering with Smart App Control.

But that’s not all – Lazarus has also deployed a new backdoor called Troy, which supports 17 commands, including system reconnaissance, file exfiltration, and remote process termination. The hackers have even used leaked credentials to compromise Roundcube installations, exploiting an authenticated PHP object-deserialization vulnerability (CVE-2025-49113) to gain remote code execution.

Check Point’s analysis reveals that the attackers have a global reach, with activity observed in South America, Western Europe, and other regions. “This new Operation Dream Job campaign focused heavily on the defense sector, particularly organizations involved in military technologies such as surveillance sensors, drones, and robotics,” the researchers say.

The Lazarus threat group has been evolving its tactics to become increasingly stealthy and adaptable to targeted environments. In this case, they have abused legitimate web infrastructure (compromised Roundcube instances) to hide malicious communications. As always, prevention is key – but even with valid credentials, only 37% of attackers’ actions are blocked.

If you’re a business or individual handling sensitive data, it’s essential to stay vigilant and up-to-date on the latest security patches and best practices. This attack serves as a reminder that even with robust defenses in place, determined hackers can still find ways to exploit vulnerabilities. Stay informed, stay protected – and always be prepared for the next threat to emerge.


Source: Bleeping Computer — 2026-08-12