Technology

Lazarus Group Used Windows Zero-Day to Target Defense Companies

The North Korea-linked hacking group exploited a previously unknown Windows vulnerability in targeted attacks against defense and aerospace organizations before Microsoft issued a patch.

The Lazarus Group, a North Korea-linked cyber-espionage group, has been identified exploiting a Windows zero-day vulnerability in a targeted campaign against defense and aerospace organizations. Researchers say the attacks were part of the group’s long-running Operation Dream Job, which commonly uses fake employment opportunities to attract targeted victims.

The vulnerability, tracked as CVE-2026-68820, affects the Windows AFD.sys driver and could allow an attacker to obtain highly elevated privileges on a compromised computer. Researchers say Lazarus exploited the flaw before Microsoft released a security update addressing it, making it a genuine zero-day attack rather than simply an attempt to exploit an already-known vulnerability.

The campaign reportedly targeted organizations and professionals connected to the defense and aerospace sectors in several countries, including France, Germany, Brazil and India. Attackers used convincing recruitment-themed lures to make their campaigns appear legitimate, demonstrating how social engineering can be combined with previously unknown software vulnerabilities to target specific organizations.

Researchers also identified a previously unseen backdoor called Troy associated with the campaign. The discovery is significant because it shows that Lazarus continues to develop new tools and techniques rather than relying exclusively on older malware. Security researchers are particularly concerned about campaigns that combine convincing social engineering with vulnerabilities capable of providing powerful access to targeted systems.

The incident highlights the continuing challenge posed by zero-day vulnerabilities, especially when they are discovered only after attackers have already used them. Microsoft’s August 2026 security updates addressed hundreds of vulnerabilities, including actively exploited flaws, reinforcing the importance of keeping Windows systems updated. For organizations handling sensitive defense, aerospace or government information, the Lazarus campaign is another reminder that cybersecurity requires both technical protections and careful scrutiny of unexpected recruitment or business communications.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button