Lazarus Hackers Exploit Windows Zero-Day to Target Defense Companies
North Korean hackers linked to the Lazarus threat group are targeting defense, aerospace, and aviation organizations by exploiting a Windows zero-day vulnerability, tracked as CVE-2026-68820, in the latest phase of their long-running “Operation Dream Job” campaign.
Microsoft fixed the vulnerability in its latest Patch Tuesday security update and classified it as actively exploited in the wild. Security researchers say Lazarus began exploiting the flaw in early July.
Microsoft describes CVE-2026-68820 as a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, also known as AFD.sys. Successful exploitation allows attackers to elevate local privileges on vulnerable Windows systems.
According to the tech giant, a locally authenticated attacker can run a specially crafted application to trigger a race condition. The attack can then be used to obtain SYSTEM-level privileges without requiring additional user interaction.
The latest Operation Dream Job attacks use fake employment opportunities to target employees at defense, aerospace, and aviation organizations in Europe and India.
In at least one incident, Lazarus infiltrated a French organization and used the compromised company as a staging point for a spear-phishing attack against another target.
Researchers at cybersecurity firm Check Point analyzed the latest Operation Dream Job activity and found that the attackers had integrated the CVE-2026-68820 exploit into a new version of the FudModule kernel-mode rootkit. The exploit reportedly targets Windows 11 builds 26100 and 26200 and is used to escalate privileges.
.jpg)
Source: Check Point
This is not the first time Lazarus has exploited a zero-day vulnerability in AFD.sys to elevate privileges and deploy the FudModule rootkit on targeted systems.
Check Point says the latest FudModule variant retains previously documented capabilities, including disabling endpoint detection and response (EDR) telemetry and interfering with security software. It also adds the ability to tamper with Windows Smart App Control.
The researchers also identified a new backdoor named Troy. The malware supports 17 commands, including:
- System and process reconnaissance
- File uploads, downloads, deletions, and archive-based data exfiltration
- Execution of hidden commands
- Termination of remote processes
- In-memory DLL injection
- Modification of configuration settings and beacon intervals
Check Point also observed scans for vulnerable Roundcube email server installations. Compromised systems were subsequently infected with a new PHP web shell called RelayShell.
The attackers may have used stolen credentials to authenticate to Roundcube before exploiting CVE-2025-49113, an authenticated PHP object deserialization vulnerability that can allow remote code execution.

Source: Check Point
Based on the number of unique identifiers collected during its investigation, Check Point identified at least 17 servers infected with the RelayShell web shell.
“This new Operation Dream Jobs campaign focuses on organizations involved in the defense sector, particularly military technologies such as surveillance sensors, drones and robotics,” Check Point says.
“The campaign spread globally, with activity extending to South America, including Brazil, and targeted success was also observed in Western Europe, including France and Germany.”
The latest findings indicate that Lazarus continues to develop stealthier cyberattacks that adapt to each target environment. In this campaign, the threat actors abused legitimate web infrastructure, including compromised Roundcube servers, to conceal malicious communications and maintain access.
Check Point’s report includes indicators of compromise linked to the campaign, along with YARA rules that organizations can use to detect RelayShell PHP web shells.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




