Lazarus exploits Windows zero-day in Dream Job attacks
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]
What Happened
North Korean state-sponsored hackers linked to the Lazarus Group are actively exploiting a Windows zero-day vulnerability, tracked as CVE-2026-68820, to compromise defense-sector companies. The attacks are part of the long-running Operation Dream Job campaign, which uses fake job recruitment lures to trick employees at military and aerospace contractors into executing malicious payloads.
The vulnerability resides in the Windows Ancillary Function Driver (AFD) and allows local privilege escalation. Lazarus combines this bug with a separate initial access vector, likely a trojanized application or a weaponized document, to gain a foothold on target systems before escalating to SYSTEM-level privileges. Microsoft has confirmed active exploitation in the wild, though a patch schedule has not yet been publicly detailed.
Why It Matters
This is not a routine espionage incident. The defense industrial base is among the most protected sectors in the world, and Lazarus successfully bypassed those defenses using a chain that includes a previously unknown kernel-level flaw. The Dream Job campaign has been active since at least 2020, but this is the first confirmed use of a Windows zero-day in this specific operation.
Organizations in adjacent sectors should treat this as a warning. Aerospace, critical infrastructure, and any company with defense supply chain relationships are at elevated risk. The combination of social engineering with a kernel privilege escalation bug means that even well-patched environments can be compromised if an employee takes the bait.
Technical Details
The attack chain begins with a lure document or fake interview request that installs a custom loader. This loader drops a payload that exploits CVE-2026-68820 to elevate privileges to SYSTEM. Once elevated, the attackers deploy a full remote access tool, typically a variant of the well-known Lazarus malware family such as COBALT STRIKE or a custom implant.
Indicators of compromise reported by researchers include unusual AFD.sys calls, unexpected process creation from the Service Host process, and outbound connections to known Lazarus command-and-control infrastructure. Analysts also flagged renamed executables in temp directories and persistence mechanisms registered via scheduled tasks.
The vulnerability affects all supported versions of Windows 10 and Windows 11, along with Windows Server 2016 through 2022. There is no evidence of in-the-wild exploitation against Windows 7 or older systems at this time.
Immediate Risk
The risk is critical and current. Microsoft has not yet released a patch, so all affected systems are exposed if an attacker gains local access. However, exploitation requires an initial foothold, which means the social engineering component is the first line of defense.
Defense contractors should treat any unsolicited recruitment emails, especially those from fake headhunters or fake company domains, as a potential attack vector. The campaign is known to target LinkedIn and email, and researchers observed a spike in activity in recent weeks.
Security Insight
This is the third time in 12 months that a North Korean threat actor has used a kernel-level flaw as part of a social engineering campaign, following similar patterns seen with the DAEMON Tools Lite supply chain attack and the Chrome sandbox escape. The trend suggests Lazarus is shifting from purely credential-based attacks to a more surgical approach that combines bug exploitation with targeted lures.
The non-obvious defensive takeaway is that endpoint detection is not the primary mitigation. The strongest control is identity verification at the recruitment channel level. If your security team does not already have a process for vetting external communications with engineering staff, that is the gap to close first. The zero-day will be patched eventually, but the social engineering component will outlive any software fix.
Further Reading
Never miss a security update
Get real-time security alerts delivered to your preferred platform.
Related News
Microsoft has pulled a buggy Windows 11 non-security preview update to investigate a known issue that triggers 0x80073712 errors during installation. [...]
Microsoft is investigating a new issue affecting some Samsung laptops running Windows 11 after installing the February 2026 security updates, in which users lose access to their C:\ drive and are
Microsoft has released the Windows 10 KB5078885 extended security update to fix the March 2026 Patch Tuesday vulnerabilities, including 2 zero-days and an issue that prevent some devices from shutting
Microsoft has released the KB5079391 preview cumulative update for Windows 11 24H2 and 25H2, which includes 29 changes, such as Smart App Control and Display improvements. [...]