Lazarus Group Exploits Windows Zero-Day Vulnerability to Deploy Backdoor Targeting Defense Firms Worldwide

Published:

spot_img

The North Korean threat actor known as Lazarus Group has exploited a newly patched zero-day vulnerability in Microsoft Windows to deploy a previously unseen backdoor targeting defense and aerospace companies in France, Germany, Brazil, and India. This activity is part of Operation Dream Job, a long-running cyber espionage campaign aimed at professionals worldwide.

According to reporting by The Hacker News, the attacks leverage the CVE-2026-68820 vulnerability, which has a CVSS score of 7.0. This privilege escalation flaw affects the Windows Ancillary Function Driver for WinSock (“AFD.sys”) and was patched by Microsoft in August 2026.

Victims are lured through fake recruiter messages and tricked into opening malicious PDFs or installing a trojanized PDF viewer. This leads to the installation of a backdoor named Troy, which grants remote access to compromised machines. The ultimate goal is to gain complete control over infected systems and bypass security measures.

Attack Methodology

Two distinct infection sequences have been identified:

  • DLL side-loading: Victims download an encrypted archive that triggers a DLL side-loading chain. A malicious DLL displays a fake job description while stealthily downloading a lightweight downloader called MISTPEN, which communicates with threat actor-controlled infrastructure.
  • Trojanized “SecurityPDF” viewer: Victims are instructed to download a PDF viewer from a site impersonating Enveil. This viewer monitors opened PDFs for specific markers and, if detected, launches a backdoor directly into memory.

The MISTPEN downloader loads various modules for reconnaissance and data exfiltration, including a local privilege escalation loader that enhances its capabilities. The attack chain employs an updated kernel-mode rootkit to evade detection by security software.

Infrastructure and Tactics

Notably, the campaign hijacks legitimate but compromised websites and vulnerable servers for command-and-control operations, making it difficult to distinguish malicious traffic from normal web activity. The attackers have also created at least three websites impersonating Enveil to distribute the trojanized PDF viewer.

Recent findings indicate that the Lazarus Group continues to refine its malware capabilities while maintaining the core elements of the Dream Job campaign, posing significant risks to critical sectors globally.

Sergey Shykevich, director of threat intelligence at Check Point Software, emphasized the dangers of this campaign, stating, “What makes this campaign so dangerous is not only the zero-day vulnerability – but also how Lazarus wove legitimate, trusted infrastructure into every stage of the attack.”

Follow Cyber Warriors Middle East for further global cybersecurity developments.

spot_img

Related articles

Recent articles

OpenAI Expands Daybreak Program to Include Specialized Cybersecurity Services

OpenAI has announced an expansion of its Daybreak program, which now includes specialized cybersecurity services aimed at enhancing defensive capabilities. This update, detailed in...

WhatsApp Launches Beta of Scam Alert Feature to Identify Suspicious Messages

WhatsApp has initiated a limited beta rollout of its Scam Alert feature, designed to identify suspicious messages from non-contacts using an on-device machine learning...

Ransomware Recovery Challenges: 34% of ANZ Organizations Still Opt to Pay Ransom Despite Uncertain Outcomes

Research published by Commvault reveals that 34% of organizations in Australia and New Zealand that experienced a ransomware attack opted to pay the ransom....

OpenAI Flags Astra Model for Critical Cybersecurity Risks, Halting Development

OpenAI has raised alarms regarding its forthcoming AI model, Astra, which may pose a ‘critical’ cybersecurity risk. This assessment has led the company to...