Critical Vulnerability

Lazarus exploits Windows zero-day in Dream Job attacks

By Yazoul AI · automated

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]

What Happened

North Korean state-sponsored hackers linked to the Lazarus Group are actively exploiting a Windows zero-day vulnerability, tracked as CVE-2026-68820, to compromise defense-sector companies. The attacks are part of the long-running Operation Dream Job campaign, which uses fake job recruitment lures to trick employees at military and aerospace contractors into executing malicious payloads.

The vulnerability resides in the Windows Ancillary Function Driver (AFD) and allows local privilege escalation. Lazarus combines this bug with a separate initial access vector, likely a trojanized application or a weaponized document, to gain a foothold on target systems before escalating to SYSTEM-level privileges. Microsoft has confirmed active exploitation in the wild, though a patch schedule has not yet been publicly detailed.

Why It Matters

This is not a routine espionage incident. The defense industrial base is among the most protected sectors in the world, and Lazarus successfully bypassed those defenses using a chain that includes a previously unknown kernel-level flaw. The Dream Job campaign has been active since at least 2020, but this is the first confirmed use of a Windows zero-day in this specific operation.

Organizations in adjacent sectors should treat this as a warning. Aerospace, critical infrastructure, and any company with defense supply chain relationships are at elevated risk. The combination of social engineering with a kernel privilege escalation bug means that even well-patched environments can be compromised if an employee takes the bait.

Technical Details

The attack chain begins with a lure document or fake interview request that installs a custom loader. This loader drops a payload that exploits CVE-2026-68820 to elevate privileges to SYSTEM. Once elevated, the attackers deploy a full remote access tool, typically a variant of the well-known Lazarus malware family such as COBALT STRIKE or a custom implant.

Indicators of compromise reported by researchers include unusual AFD.sys calls, unexpected process creation from the Service Host process, and outbound connections to known Lazarus command-and-control infrastructure. Analysts also flagged renamed executables in temp directories and persistence mechanisms registered via scheduled tasks.

The vulnerability affects all supported versions of Windows 10 and Windows 11, along with Windows Server 2016 through 2022. There is no evidence of in-the-wild exploitation against Windows 7 or older systems at this time.

Immediate Risk

The risk is critical and current. Microsoft has not yet released a patch, so all affected systems are exposed if an attacker gains local access. However, exploitation requires an initial foothold, which means the social engineering component is the first line of defense.

Defense contractors should treat any unsolicited recruitment emails, especially those from fake headhunters or fake company domains, as a potential attack vector. The campaign is known to target LinkedIn and email, and researchers observed a spike in activity in recent weeks.

Security Insight

This is the third time in 12 months that a North Korean threat actor has used a kernel-level flaw as part of a social engineering campaign, following similar patterns seen with the DAEMON Tools Lite supply chain attack and the Chrome sandbox escape. The trend suggests Lazarus is shifting from purely credential-based attacks to a more surgical approach that combines bug exploitation with targeted lures.

The non-obvious defensive takeaway is that endpoint detection is not the primary mitigation. The strongest control is identity verification at the recruitment channel level. If your security team does not already have a process for vetting external communications with engineering staff, that is the gap to close first. The zero-day will be patched eventually, but the social engineering component will outlive any software fix.

Further Reading

Share:

Never miss a security update

Get real-time security alerts delivered to your preferred platform.

Related News

Related Across Yazoul

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.