Skip to content
Tech News
← Back to articles

Lazarus hackers exploited Windows zero-day to target defense firms

read original more articles
Why This Matters

The exploitation of a Windows zero-day vulnerability by North Korean Lazarus hackers underscores the ongoing cybersecurity threats facing defense and aerospace sectors. This highlights the importance of timely security updates and advanced threat detection to protect sensitive information and infrastructure. The attack also emphasizes the evolving tactics of nation-state actors in leveraging sophisticated exploits for espionage and sabotage.

Key Takeaways

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign.

Microsoft addressed the flaw in this month's Patch Tuesday security updates, marking it as actively exploited in the wild. Researchers found that the Lazarus threat group has been leveraging it since early July.

Microsoft says that the vulnerability is a "use-after-free in Windows Ancillary Function Driver for WinSock (AFD.sys)" that allows an attacker to increase their local privileges.

The tech giant added that a locally authenticated user could run a specially crafted application on an affected system to trigger a race condition, eventually gaining SYSTEM privileges without any user interaction.

A recent wave of the long-standing Operation Dream Job campaign has been targeting defense, aerospace, and aviation organizations in Europe and India, using fraudulent recruitment offers to employees in target entities.

In at least one case, the threat actor compromised an organization in France and used it in spear-phishing attacks on additional targets.

Researchers at cybersecurity company Check Point, tracking the latest variant of Operation Dream Job, found that Lazarus incorporated an exploit for CVE-2026-68820 that specifically supported Windows 11 builds 26100 and 26200 into a new version of the FudModule kernel-mode rootkit to elevate privileges.

Lazarus' latest infection chain

Source: Check Point

This is not the first time Lazarus exploited a zero-day flaw in AFD.sys to elevate privileges and install the FudModule rootkit on targeted systems.

... continue reading