North Korean hackers linked to the Lazarus group have exploited a Windows zero-day to target organizations in the defense, aerospace, and aviation sectorsThe attacks are connected to Operation Dream Job, where attackers pose as recruiters and use job opportunities to approach potential victims Researchers found activity affecting targets in Western Europe and India, with additional activity reported in Brazil and other regionsThe campaign shows how job-related social engineering is being combined with a Windows security flaw

The vulnerability is tracked as CVE-2026-68820 and affects the Windows Ancillary Function Driver for WinSock, known as AFD.sys Microsoft describes it as a use-after-free vulnerability that can allow a locally authenticated attacker to increase privileges on a system A specially crafted application can trigger a race condition and provide SYSTEM-level access without requiring user interaction Microsoft fixed the vulnerability on August 11, 2026, as part of its August Patch Tuesday security updates
Check Point researchers discovered the zero-day while investigating the Operation Dream Job activity and reported it to Microsoft Their investigation found that Lazarus had been using the vulnerability since at least early July, before a security update was available The researchers also found an exploit designed to work against Windows 11 builds 26100 and 26200 The exploit was added to a version of FudModule, a Lazarus kernel-mode rootkit used to gain control over compromised systems

The attacks often begin with job offers that are designed to make the target trust the attackerIn one infection chain, victims were persuaded to download a ZIP archive containing a legitimate signed PDF viewer, a malicious DLL, and an encrypted payload disguised as a PDFWhen the viewer was launched, DLL sideloading caused the malicious library to run while a document was displayed In one case, the decoy document used a Lockheed Martin job description
A second infection chain used a modified PDF viewer called SecurityPDF, based on the open-source MuPDF project and made to appear connected to privacy technology company Enveil Lazarus created websites impersonating Enveil to distribute the modified viewer, with some appearing high in search results The attackers then used malicious PDF files to deliver malware Check Point said there was no evidence that Enveil itself had been compromised, showing how trusted names were used to make the operation look legitimate

After the initial infection, the attackers used MISTPEN, an in-memory downloader that collects information about the target and retrieves components Once the target was considered valuable, the attackers used the CVE-2026-68820 exploit to gain SYSTEM privileges and deploy FudModule The updated rootkit can interfere with security monitoring and security products, while the campaign also introduced Troy, a backdoor capable of reconnaissance, file operations, hidden command execution, remote process termination, and in-memory DLL injection
Lazarus also used web infrastructure to make its communications harder to identifyResearchers found Roundcube servers and other websites being used to relay command-and-control traffic Some Roundcube systems were vulnerable to CVE-2025-49113, and researchers believe stolen credentials may have been used before attackers exploited the flaw and installed a PHP web shell called RelayShell At least 17 compromised relay servers were identified, helping attackers hide malicious traffic among web activity

The campaign is important because it combines fake recruitment, malicious software, zero-day exploitation, and compromised infrastructure in one operation focused heavily on defense technology Check Point observed targeting of organizations involved in areas such as surveillance sensors, drones, and robotics Microsoft has released a fix for CVE-2026-68820, while CISA has ordered U.S. federal agencies to patch the vulnerability by August 25Organizations using affected Windows systems should prioritize the update and review suspicious recruitment activity and endpoint behavior
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news