North Korean Lazarus Hackers Exploit Windows Zero-Day in Defense Sector Attacks
North Korea's Lazarus hacking group actively exploits a Windows zero-day vulnerability known as CVE-2026-68820 to infiltrate defense, aerospace, and aviation companies across Europe and India. The campaign, dubbed Operation Dream Job, uses fake recruitment offers to trick employees at targeted organizations. Microsoft addresses the flaw in its latest Patch Tuesday updates after researchers discover the threat actors have been leveraging it since early July.
The vulnerability exists as a use-after-free bug in the Windows Ancillary Function Driver for WinSock, allowing attackers to escalate local privileges and gain full SYSTEM access. Lazarus integrates this exploit into a new version of its FudModule kernel-mode rootkit, which not only disables security product telemetry but also adds the ability to tamper with Smart App Control. This approach mirrors previous Lazarus operations that targeted the same Windows driver component for privilege elevation.
Researchers at Check Point also uncover a new backdoor called Troy that the hackers deploy alongside the rootkit. Troy supports 17 distinct commands, enabling file exfiltration, hidden command execution, remote process termination, and in-memory DLL injection. The threat actors further expand their toolkit by scanning for vulnerable Roundcube email installations and compromising them with a newly developed PHP web shell known as Rel.