Lazarus Group Exploits Windows Zero-Day Vulnerability to Deploy Backdoor Targeting Defense Firms Worldwide

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

The North Korean threat actor known as Lazarus Group has exploited a newly patched zero-day vulnerability in Microsoft Windows to deploy a previously unseen backdoor targeting defense and aerospace companies in France, Germany, Brazil, and India. This activity is part of Operation Dream Job, a long-running cyber espionage campaign aimed at professionals worldwide.

According to reporting by The Hacker News, the attacks leverage the CVE-2026-68820 vulnerability, which has a CVSS score of 7.0. This privilege escalation flaw affects the Windows Ancillary Function Driver for WinSock (“AFD.sys”) and was patched by Microsoft in August 2026.

Victims are lured through fake recruiter messages and tricked into opening malicious PDFs or installing a trojanized PDF viewer. This leads to the installation of a backdoor named Troy, which grants remote access to compromised machines. The ultimate goal is to gain complete control over infected systems and bypass security measures.

Attack Methodology

Two distinct infection sequences have been identified:

  • DLL side-loading: Victims download an encrypted archive that triggers a DLL side-loading chain. A malicious DLL displays a fake job description while stealthily downloading a lightweight downloader called MISTPEN, which communicates with threat actor-controlled infrastructure.
  • Trojanized “SecurityPDF” viewer: Victims are instructed to download a PDF viewer from a site impersonating Enveil. This viewer monitors opened PDFs for specific markers and, if detected, launches a backdoor directly into memory.

The MISTPEN downloader loads various modules for reconnaissance and data exfiltration, including a local privilege escalation loader that enhances its capabilities. The attack chain employs an updated kernel-mode rootkit to evade detection by security software.

Infrastructure and Tactics

Notably, the campaign hijacks legitimate but compromised websites and vulnerable servers for command-and-control operations, making it difficult to distinguish malicious traffic from normal web activity. The attackers have also created at least three websites impersonating Enveil to distribute the trojanized PDF viewer.

Recent findings indicate that the Lazarus Group continues to refine its malware capabilities while maintaining the core elements of the Dream Job campaign, posing significant risks to critical sectors globally.

Sergey Shykevich, director of threat intelligence at Check Point Software, emphasized the dangers of this campaign, stating, “What makes this campaign so dangerous is not only the zero-day vulnerability – but also how Lazarus wove legitimate, trusted infrastructure into every stage of the attack.”

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...

NASA’s SARSAT technology aids in rescue of five fishermen at sea

NASA's Search and Rescue Satellite-Aided Tracking (SARSAT) technology played a crucial role in the rescue of five fishermen off the Gulf Coast of Mississippi...