North Korean Lazarus hackers exploit Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies in Europe and India as part of the Operation Dream Job campaign, BleepingComputer reports citing researchers at Check Point.
Microsoft patched the flaw this month, describing it as a use-after-free vulnerability in Windows Ancillary Function Driver for WinSock that allows attackers to escalate privileges to SYSTEM level. Lazarus incorporated an exploit for the vulnerability into a new version of the FudModule kernel-mode rootkit, which disables endpoint detection and response telemetry and interferes with security products.
Check Point found that the latest wave of Operation Dream Job, which has used fraudulent recruitment offers to target employees, also deployed a new backdoor called Troy supporting 17 commands including file exfiltration and remote process termination.

















