A five-week zero-day campaign linked to Pyongyang has compromised aerospace and defense personnel across four countries, with a federal remediation deadline now eleven days out.

Intelligence Lead

North Korea's Lazarus Group weaponized a previously unknown Windows kernel vulnerability for at least five weeks before Microsoft issued a patch, using it to install a new backdoor on machines belonging to defense and aerospace workers in France, Germany, Brazil, and India. The campaign, an extension of the long-running Operation Dream Job social-engineering effort, combines fabricated recruiter outreach with a kernel-level rootkit capable of blinding Windows' own security telemetry. CISA has already added the flaw to its Known Exploited Vulnerabilities catalog, giving US federal agencies until 25 August to remediate.

Situation Report

Researchers assess with high confidence that Lazarus Group, a hacking apparatus attributed to North Korea's Reconnaissance General Bureau, exploited CVE-2026-68820, a use-after-free privilege-escalation flaw in AFD.sys, the Windows driver that governs network socket operations. Microsoft patched the vulnerability on 11 August as part of its scheduled Patch Tuesday release; CISA added it to the Known Exploited Vulnerabilities catalog the same day. Forensic timestamps recovered from a compiled rootkit artifact place the earliest confirmed exploitation at 7 July, indicating the operators held and used the zero-day undetected for roughly five weeks.

The intrusion path follows the established Operation Dream Job model. Targets employed at or adjacent to defense and aviation firms, among them entities resembling Lockheed Martin and the AI-security firm Enveil, were approached on LinkedIn by accounts posing as recruiters offering high-value roles. Victims who engaged were directed to a malicious PDF or a trojanized PDF viewer, which delivered a previously undocumented backdoor researchers have named Troy. Troy granted the operators remote access sufficient to escalate privileges using the AFD.sys flaw and deploy FudModule, a kernel-level rootkit Lazarus has used in prior campaigns to disable Windows' own monitoring stack.

Once embedded, FudModule reportedly disabled 94 separate Event Tracing for Windows channels and interfered with Smart App Control, Microsoft's application-trust enforcement layer, effectively blinding endpoint defenses to the operators' subsequent activity on compromised hosts. Confirmed targeting spans France, Germany, Brazil, and India, with the defense and aerospace sectors named specifically; researchers caution the true victim set may extend further, given the campaign's five-week undetected run.

Background & Context

Operation Dream Job has run for several years as one of Lazarus Group's primary vectors into Western and allied defense-industrial targets, prioritizing human intelligence-style social engineering over pure technical exploitation. The campaign's persistence reflects Pyongyang's dual strategic interest in the defense sector: acquisition of restricted weapons and aerospace technology, and generation of hard currency through parallel financially motivated Lazarus operations. Kernel-level rootkits such as FudModule have become a signature escalation tool for the group, allowing operators to defeat endpoint detection products that rely on Windows' native telemetry.

The AFD.sys vulnerability itself sits in a component of Windows with a history of privilege-escalation flaws, given its low-level handling of network socket calls across nearly all Windows installations. That breadth, combined with the five-week window between first use and patch availability, is what elevates this incident from a routine advisory to a strategic concern: the exploit was live against defense-sector targets during a period when no public detection signature existed.

Analysis & Assessment

The incident reinforces an assessed pattern in North Korean cyber operations: technical sophistication paired with low-cost social engineering remains more reliable than novel intrusion vectors alone. Lazarus's willingness to burn a Windows kernel zero-day against a relatively narrow, high-value target set, rather than deploying it broadly, suggests operational discipline aimed at maximizing dwell time over volume, a hallmark of state-directed rather than criminal tasking.

The eleven-day remediation window CISA has set for US federal civilian agencies is likely to be treated as a floor rather than a ceiling by allied defense-industrial base entities in the named countries, given that patch availability does not retroactively identify hosts compromised during the five-week exploitation window. Organizations in the defense, aerospace, and adjacent supply chain sectors should assess for indicators tied to the Troy backdoor and FudModule rootkit regardless of patch status, since successful prior compromise would predate the fix. Expect continued LinkedIn-vector targeting of cleared or defense-adjacent personnel as the primary access method, with technical escalation tools evolving faster than detection signatures can be distributed.