Lazarus hackers exploited Windows zero-day to target defense firms
AI Generated Image

Lazarus hackers exploited Windows zero-day to target defense firms

BleepingComputer technology

Key Points:

  • North Korean hacker group Lazarus has been exploiting a Windows zero-day vulnerability (CVE-2026-68820) in the Operation Dream Job campaign, targeting defense, aerospace, and aviation companies globally, including in Europe, India, and South America.
  • The vulnerability is a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys) that allows local privilege escalation to SYSTEM level without user interaction, addressed by Microsoft in the latest Patch Tuesday updates.
  • Lazarus has integrated the exploit into a new version of their FudModule kernel-mode rootkit, enhancing capabilities like disabling EDR telemetry, tampering with Smart App Control, and deploying a new backdoor called Troy with extensive system control functions.
  • The attackers have also compromised Roundcube email servers using leaked credentials and CVE-2025-49113, deploying a PHP webshell named RelayShell to facilitate remote code execution and maintain stealthy communications.
  • Check Point researchers highlight the campaign's focus on military technology sectors and note Lazarus's evolution towards more covert operations by abusing legitimate web infrastructure, providing indicators of compromise and detection tools for defenders.

Trending Business

Trending Technology

Trending Health