Lazarus hackers exploited Windows zero-day to target defense firms

2 hours ago 7

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign.

Microsoft addressed the flaw in this month's Patch Tuesday security updates, marking it as actively exploited in the wild. Researchers found that the Lazarus threat group has been leveraging it since early July.

Microsoft says that the vulnerability is a "use-after-free in Windows Ancillary Function Driver for WinSock (AFD.sys)" that allows an attacker to increase their local privileges.

image

The tech giant added that a locally authenticated user could run a specially crafted application on an affected system to trigger a race condition, eventually gaining SYSTEM privileges without any user interaction.

A recent wave of the long-standing Operation Dream Job campaign has been targeting defense, aerospace, and aviation organizations in Europe and India, using fraudulent recruitment offers to employees in target entities.

In at least one case, the threat actor compromised an organization in France and used it in spear-phishing attacks on additional targets.

Researchers at cybersecurity company Check Point, tracking the latest variant of Operation Dream Job, found that Lazarus incorporated an exploit for CVE-2026-68820 that specifically supported Windows 11 builds 26100 and 26200 into a new version of the FudModule kernel-mode rootkit to elevate privileges.

Lazarus' latest infection chainLazarus' latest infection chain
Source: Check Point

This is not the first time Lazarus exploited a zero-day flaw in AFD.sys to elevate privileges and install the FudModule rootkit on targeted systems.

According to the researchers, the latest version of the rootkit features previously documented capabilities such as disabling EDR telemetry and interfering with security products, while also adding Smart App Control tampering.

Check Point's analysis revealed that the hackers have also deployed a new backdoor called Troy that supports 17 commands, including the following:

  • System and process reconnaissance
  • File upload, download, deletion, and archive-based exfiltration
  • Hidden command execution
  • Remote process termination
  • In-memory DLL injection
  • Configuration and beacon timing changes

Check Point also reported observing scans targeting vulnerable Roundcube installations, which were subsequently compromised with a new PHP web shell dubbed RelayShell.

The attacker likely used leaked credentials to authenticate to Roundcube before exploiting CVE-2025-49113, an authenticated PHP object-deserialization vulnerability, to obtain remote code execution.

RelayShell commandsRelayShell commands
Source: Check Point

The researchers have identified at least 17 servers infected with RelayShell, based on the number of identifiers they retrieved.

“This new Operation Dream Job campaign focused heavily on the defense sector, particularly organizations involved in military technologies such as surveillance sensors, drones, and robotics,” Check Point says.

“The campaign had a global reach, with activity extending into South America, including Brazil, and successful targeting observed in Western Europe, including France and Germany.”

The researchers say that its latest findings confirm that Lazarus has further evolved into stealthier operations that adapt to targeted environments. In this case, the attacker abused legitimate web infrastructure (compromised Roundcube instances) to hide malicious communications.

Check Point's report shares a list of indicators of compromise related to the attacks, as well as a YARA rule to help detect the RelayShell webshell.

article image

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Read Entire Article