Lazarus hackers exploited Windows zero-day to target defense firms

Lazarus Hackers Unleash Sophisticated Attack on Defense Sector Using Zero-Day Vulnerity

North Korean threat group Lazarus has been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense firms in Europe and India as part of its long-standing Operation Dream Job campaign. The hackers have used the flaw, which was patched by Microsoft earlier this month, to gain SYSTEM privileges on affected systems without requiring user interaction.

The vulnerability, located in the Windows Ancillary Function Driver for WinSock (AFD.sys), allows an attacker to increase their local privileges and execute a specially crafted application on an affected system. This can lead to a race condition, ultimately granting the hacker access to sensitive areas of the system. Researchers at cybersecurity company Check Point found that Lazarus incorporated an exploit for CVE-2026-68820 into its FudModule kernel-mode rootkit, allowing it to elevate privileges and install additional malicious components.

The Operation Dream Job campaign has been targeting defense, aerospace, and aviation organizations using fraudulent recruitment offers to lure employees into downloading malware. In at least one case, the threat actor compromised an organization in France and used it as a springboard for spear-phishing attacks on other targets. The latest variant of the rootkit features capabilities such as disabling EDR telemetry and interfering with security products, while also adding support for tampering with Smart App Control.

Check Point’s analysis revealed that Lazarus has also deployed a new backdoor called Troy, which supports 17 commands, including system and process reconnaissance, file upload and download, and hidden command execution. The researchers observed scans targeting vulnerable Roundcube installations, which were subsequently compromised using an authenticated PHP object-deserialization vulnerability (CVE-2025-49113) to obtain remote code execution.

This campaign highlights the evolving nature of Lazarus’ operations, with a focus on stealthy tactics that adapt to targeted environments. The attacker abused legitimate web infrastructure, such as compromised Roundcube instances, to hide malicious communications. Check Point’s report shares indicators of compromise related to the attacks and provides a YARA rule to help detect the RelayShell webshell.

The success of these attacks underscores the importance of maintaining up-to-date security patches and monitoring for suspicious activity. As seen in this campaign, once attackers gain valid credentials, prevention scores drop sharply, highlighting the need for continuous vigilance and proactive measures to mitigate potential threats.


Source: Bleeping Computer — 2026-08-12