Zero Day Room
Live
Regulation & compliance

Lazarus Group Exploits Windows Zero-Day Vulnerability to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.

Lazarus Group Exploits Windows Zero-Day Vulnerability to Gain SYSTEM Access and Deploy Backdoor

## Lazarus Group Exploits Windows Zero-Day Vulnerability The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. ## Operation Dream Job The activity is part of Operation Dream Job, a long-running cyber espionage and social engineering campaign orchestrated by Pyongyang-backed hackers to target professionals worldwide with fake-but-compelling job offers at firms like Lockheed Martin and Enveil to steal sensitive data and install malware by approaching them on platforms like LinkedIn, pretending to be recruiters in an attempt to build trust. ## Exploiting CVE-2026-68820 The attacks have been found to exploit CVE-2026-68820, a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys") that was patched by Microsoft as part of its Patch Tuesday updates for August 2026. Check Point Research reported the vulnerability to Microsoft in late July 2026, although it said "we are familiar with a successful implementation of the CVE in the beginning of June." ## Attack Chain The attack chain employs an updated version of the known kernel-mode rootkit the Lazarus Group has repeatedly employed since at least 2022 to conceal the presence of malicious tools from security software installed on the host. Specifically, it exploits a local privilege escalation vulnerability in "AFD.sys," obtains SYSTEM privileges, and ultimately injects another instance of MISTPEN into a SYSTEM process so as to allow it to run with elevated privileges and away from the eyes of security tools. ## Trojanized PDF Viewer The attackers also use a trojanized PDF viewer, called SecurityPDF, to deliver the backdoor. Victims are instructed to download SecurityPDF from a website impersonating Enveil. Once installed, it monitors for any PDF document opened through it for a special marker. If such a marker is present, the application decrypts and launches an embedded payload that's responsible for loading a backdoor called Troy directly into memory. ## Hijacking Legitimate Infrastructure The attackers have also been found to hijack legitimate but compromised WordPress and SharePoint websites and vulnerable Roundcube webmail servers for use as ForestTiger command-and-control (C2) servers. This makes it a lot more challenging to differentiate it from normal web traffic. ## Conclusion The latest findings show that Lazarus Group continues to hone its malware capabilities and tradecraft, while keeping the foundations of Dream Job largely intact in attacks aimed at critical sectors across the world. As Check Point's director of threat intelligence, Sergey Shykevich, said, "What makes this campaign so dangerous is not only the zero-day vulnerability - but also how Lazarus wove legitimate, trusted infrastructure into every stage of the attack.

Related coverage

More from Regulation & compliance