Skip to content

Lazarus Group Uses Fake Defense Industry Job Offers and Windows Zero-Day for Targeted Attacks

In brief: Lazarus combined fake job offers from well-known defense contractors with a new backdoor and a Windows zero-day vulnerability (CVE-2026-68820) to gain SYSTEM privileges on target systems.

The North Korean hacking group Lazarus has targeted employees in the defense and aerospace industry in Germany, France and India with fake job offers as part of its “Dream Job” campaign. Check Point Research uncovered a previously unknown backdoor as well as a now-patched zero-day vulnerability in Windows.

Active since 2020, the “Dream Job” campaign run by the North Korean group Lazarus, in its latest variant, specifically targeted employees at defense and aerospace companies in Germany, France and India. According to Check Point Research, the attackers lured victims with purported job offers from well-known companies such as Lockheed Martin and Enveil. The corresponding websites were in some cases specifically search-engine optimized so that they ranked highly in relevant Google searches and appeared to be legitimate career portals.

Anyone who responded to the offers and downloaded application software — for instance a supposed PDF viewer named “SecurityPDF” — actually installed a trojan. In the background, the malware “Troy” was launched, a previously undocumented modular backdoor with 17 different commands for controlling infected systems. In addition, Lazarus deployed a new version 3.1 of the FudModule rootkit.

A central element of the attack chain was the Windows vulnerability CVE-2026-68820 in the Microsoft driver AFD.sys. The previously unknown vulnerability allowed the attackers to obtain SYSTEM privileges and bypass security mechanisms on the endpoints. Check Point Research reported the vulnerability to Microsoft as part of a responsible disclosure process; the patch was released as part of Patch Tuesday on August 11, 2026.

For communication between infected systems and the attackers, Lazarus abused compromised infrastructure belonging to legitimate organizations, including hacked Roundcube webmail installations and content management systems, in some cases via the still-open vulnerability CVE-2025-49113. At least 17 compromised servers were repurposed as communication relays using a new RelayShell web shell, in some cases using credentials from earlier dark web leaks.

For security leaders at defense and aerospace companies, this results in a multi-layered risk: social engineering via career portals, unknown malware modules, and the exploitation of already-compromised third-party infrastructure as an attack platform. In one documented case, Lazarus used an already infiltrated organization based in France to launch further spear-phishing attacks from its infrastructure — an indication that even external communication partners classified as trustworthy can serve as an attack vector. Organizations should prioritize deploying the Windows patch from August 11, 2026, and review application processes as well as external communication channels for unusual patterns.


Source: www.it-daily.net · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: