North Korean state hackers used a Windows kernel flaw and fake job offers to breach defense and aerospace targets in four countries before Microsoft's patch closed the window.
Intelligence Lead
North Korea's Lazarus Group ran a Windows kernel zero-day exploit for at least five weeks against defense and aerospace firms in France, Germany, Brazil, and India, gaining SYSTEM-level access before Microsoft closed the flaw on August 11. The campaign, folded into the long-running Operation Dream Job social-engineering line, combined fraudulent recruiter outreach with a trojanized PDF viewer to deliver a previously undocumented backdoor, extending Pyongyang's reach into contractor networks tied to sensitive defense-industrial supply chains.
Situation Report
Security researchers confirmed that Lazarus Group exploited CVE-2026-68820, a use-after-free race condition in the Windows afd.sys driver, to escalate privileges to SYSTEM level on compromised machines. A compiled rootkit artifact tied to the intrusion carries a build timestamp of July 7, 2026, indicating the exploit was operational roughly five weeks before Microsoft issued a patch in its August 11 Patch Tuesday release. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog the same day, setting a remediation deadline of August 25 for US civilian executive branch agencies.
Documented infection chains show attackers impersonating the privacy technology firm Enveil in fraudulent recruitment outreach, directing targets to download SecurityPDF, a modified build of an open-source PDF viewer. Opening an attacker-prepared document in that application triggered execution of an embedded payload installing Troy, a newly identified backdoor providing remote access to the host. Confirmed victims span the defense and aerospace sectors across France, Germany, Brazil, and India.
Investigators further assessed that Lazarus compromised at least 17 third-party servers, including Roundcube webmail, WordPress, and PrestaShop installations, to host a PHP webshell designated RelayShell, functioning as an anonymous bidirectional relay layer for operator traffic. A separate in-memory downloader, MISTPEN, routed command-and-control communications through Microsoft's Graph API and OneDrive infrastructure, blending malicious traffic with legitimate enterprise usage patterns to evade detection.
Background & Context
Operation Dream Job is a persistent Lazarus Group initiative, active since at least 2020, that lures targets in defense, aerospace, and technology sectors with fabricated job offers from well-regarded firms. The campaign has previously been linked to intrusions against aerospace and defense contractors in the United States and Europe, and forms part of a broader North Korean state effort to acquire military technology, generate revenue through cryptocurrency theft, and sustain long-term access inside allied defense-industrial networks under sustained UN and unilateral sanctions pressure.
The use of a Windows kernel zero-day marks an escalation in tradecraft sophistication for a group more commonly associated with social engineering and supply-chain compromise than novel exploit development. Pairing a kernel-level privilege escalation flaw with living-off-trusted-services infrastructure, including Microsoft's own cloud APIs for command and control, reflects deliberate investment in detection evasion against Western enterprise security tooling.
Analysis & Assessment
Analysts assess with high confidence that this campaign reflects continued North Korean state prioritization of defense-industrial espionage alongside its more familiar financially motivated cybercrime operations, with Lazarus subunits routinely pursuing both objectives in parallel. The five-week gap between first observed exploitation and public disclosure indicates either delayed detection by targeted organizations or deliberate operational patience by the threat actor, both of which point to monitoring gaps across contractor networks that sit adjacent to, but outside, primary defense-prime security perimeters.
The compromise of legitimate third-party infrastructure for relay purposes complicates attribution and takedown efforts, and is likely to recur across future Lazarus operations given its demonstrated effectiveness here. Second- and third-tier suppliers across the defense-industrial base, which typically operate less mature security programs than prime contractors, should be assessed as elevated-priority targets for follow-on Lazarus activity through the remainder of 2026.