North Korea's Lazarus Group exploited a Windows zero-day to target defense firms
North Korea's Lazarus Group exploited a Windows zero-day, CVE-2026-68820, since early July to target defense and aerospace firms in Europe and India, according to Check Point Research. The campaign used fake recruiter messages impersonating firms like Lockheed Martin $LMT to install a new backdoor called Troy. Microsoft $MSFT patched the flaw on August 11.
North Korea's Lazarus Group exploited a previously unknown Windows flaw, CVE-2026-68820, as a zero-day since at least early July, weeks before Microsoft $MSFT patched it on August 11. Check Point Research says the vulnerability sits in AFD.sys, the driver behind Windows networking, and lets an attacker gain full system privileges through a race condition. As part of its long-running Operation Dream Job campaign, Lazarus sent fake recruiter messages impersonating real firms including Lockheed Martin $LMT and Enveil, and infected victims with a new backdoor called Troy that supports seventeen remote commands. Check Point traced confirmed activity to organizations in France, Germany, Brazil and India, with a focus on companies working on surveillance sensors, drones and robotics. The campaign also hijacked at least seventeen compromised Roundcube mail servers to hide its command traffic inside otherwise legitimate web infrastructure.