Friday, August 14, 2026

Independent technology reporting and practical analysis

Manila ·
TECHNOLOGY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Technology / news

Lazarus Hackers Exploit Windows Zero-Day to Target Defense Firms

North Korean hackers used a Windows zero-day vulnerability in the AFD.sys driver to breach defense-sector companies through fraudulent job offers, according to researchers.

Illustration representing the Lazarus hacking group targeting Windows systems
Illustration representing the Lazarus hacking group targeting Windows systems

North Korean state-sponsored hacking group Lazarus has been exploiting a Windows zero-day vulnerability to compromise defense-sector organizations across Europe and India, according to a report from BleepingComputer. The attacks are part of the long-running Operation Dream Job campaign, which uses fraudulent job offers to lure employees at targeted companies.

Microsoft patched the flaw, tracked as CVE-2026-68820, in its most recent Patch Tuesday release and flagged it as actively exploited in the wild. The vulnerability is a use-after-free bug in the Windows Ancillary Function Driver for WinSock (AFD.sys). A locally authenticated attacker can exploit it by running a specially crafted application to trigger a race condition, ultimately gaining SYSTEM privileges without user interaction. Researchers say Lazarus has been leveraging the zero-day since early July.

Check Point researchers analyzed the latest wave of Operation Dream Job and found that Lazarus integrated an exploit for CVE-2026-68820 into a new version of its FudModule kernel-mode rootkit. This exploit specifically supports Windows 11 builds 26100 and 26200. The updated rootkit retains previously documented features such as disabling endpoint detection and response (EDR) telemetry and interfering with security products, and it adds the ability to tamper with Smart App Control.

This is not the first time Lazarus has abused an AFD.sys zero-day to install the FudModule rootkit. Check Point also discovered that the hackers deployed a new backdoor named Troy, which supports 17 commands. The report did not list the full command set.

The campaign targeted defense, aerospace, and aviation companies in Europe and India using fake recruitment offers. In at least one case, the attackers compromised an organization in France and then used its infrastructure for spear-phishing additional targets.

Check Point also observed scanning activity against vulnerable Roundcube webmail installations. The attackers likely used leaked credentials to authenticate to Roundcube before exploiting CVE-2025-49113, an authenticated PHP object-deserialization vulnerability, to achieve remote code execution. They then deployed a new PHP web shell called RelayShell. Based on identifiers collected during the investigation, researchers identified at least 17 servers infected with RelayShell.

Check Point stated that this campaign heavily focused on the defense sector, particularly organizations involved in military technologies such as surveillance sensors, drones, and robotics. The activity had a global reach, extending into South America including Brazil, and successful targeting was observed in Western Europe, including France and Germany.

The researchers conclude that Lazarus is evolving toward stealthier operations that adapt to targeted environments. In this campaign, the group abused legitimate web infrastructure—compromised Roundcube servers—to hide malicious communications. Check Point published indicators of compromise and a YARA rule to help detect the RelayShell web shell.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Editorial illustration of a humanoid robot surrounded by neural networks, browser interfaces, code and an AI video timeline.
AI

AI's Biggest Week: GPT-5.6 Gets 80% Cheaper, Gemini Controls Humanoid Robots, and LinkedIn Fights AI Slop

USB plug connected to a Windows computer, representing Plug and Pwn attacks
Technology

Plug and Pwn: Emulated USB Devices Force Windows to Install Vulnerable Software, Researchers Warn

Enterprise data infrastructure supporting trusted AI agents
Technology

Survey: AI Agents Access Less Than Half of Enterprise Data on Average