August 12, 2026•4 min read

North Korean Hackers Exploit Windows Zero-Day Vulnerability

North Korean hackers have exploited a new Windows zero-day vulnerability, leading to cyberattacks on defense and aerospace sectors in several countries.

A cybersecurity team meeting discussing recent vulnerabilities and threats.

Recent Cyberattacks by North Korean Hackers

North Korean hackers are currently exploiting a newly patched Windows zero-day vulnerability, raising alarms among cybersecurity experts. According to Check Point, this vulnerability has enabled attackers from the notorious Lazarus Group APT to compromise systems worldwide. The ongoing attacks are part of a long-established campaign dubbed Operation Dream Job, which targets job seekers with counterfeit employment offers at reputable organizations.

The Vulnerability in Focus

The defect in question is a zero-day vulnerability in the Ancillary Function Driver for WinSock, tracked as CVE-2026-68820. This use-after-free vulnerability allows attackers to trigger a race condition to gain System privileges. Microsoft issued a patch for this vulnerability on August 11, 2026, during its Patch Tuesday updates. Following the patch, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to implement the patch within a two-week timeframe.

Attack Methodology

The hackers employ various tactics to compromise victims' systems. The infection typically begins with the delivery of a malicious payload disguised as an employment offer. This is facilitated through popular professional networks and direct messaging applications. Victims are misled into downloading a ZIP archive that contains a malicious Dynamic Link Library (DLL) along with a PDF viewer and encrypted payload designed to look like a legitimate PDF file.

DLL Sideloading and Initial Infection

In one infection chain, attackers leverage DLL sideloading to execute the Mistpen malware downloader directly in memory. While a decoy job description is presented on the screen, recon and persistence techniques are employed to explore system vulnerabilities.

Subsequent Exploits and Backdoor Deployments

Following the initial compromise, the attackers deploy ForestTiger, a backdoor associated with Lazarus, allowing further access and control over infected systems. Additionally, a separate infection path utilizes the trojanized PDF viewer named SecurityPDF, which executes the Troy backdoor directly in memory. This newly identified DLL implant enables 17 operator commands, facilitating extensive system manipulation including data exfiltration and shell access.

Targeted Sectors and Countries

Targeted SectorCountries Affected
AerospaceFrance
DefenseGermany
AviationBrazil
AerospaceIndia

The fresh campaign has focused on the defense and aerospace sectors across multiple countries, particularly in Europe and India. As per Check Point, organizations in France, Germany, Brazil, and India have been primary targets of these malicious activities. The choice of sectors and regions reflects the strategic interests of the Lazarus Group, known for targeting industries relevant to national security.

Map highlighting countries targeted by North Korean cyberattacks.

Command and Control Infrastructure

In these attacks, the command-and-control (C&C) infrastructure includes compromised Roundcube webmail deployments and various content management system (CMS) platforms. Many of these platforms have been found vulnerable to the CVE-2025-49113, a remote code execution (RCE) vulnerability that has been exploited since June 2025. This dynamic allows attackers to maintain ongoing communication with infected endpoints via a PHP webshell known as RelayShell. Unlike standard backdoors, RelayShell operates more like a communication relay, transferring commands and responses through uncomplicated text files.

Recommendations for Security Teams

Given the current threat landscape incorporating a zero-day vulnerability and new backdoor capabilities, security teams in affected sectors must prioritize immediate responses. Check Point advises that organizations conduct thorough reviews of the indicators of compromise (IoCs) associated with these attacks. It’s crucial to implement the August Patch Tuesday updates and apply vigilance to unsolicited recruiting efforts, treating them with the same caution as unverified download requests.

Broader Implications of the Attacks

The implications of these cyberattacks highlight the vulnerabilities present not only in individual systems but also across entire sectors critical to national security. With enhanced targeting of industries involved in defense and aerospace, the need for robust cybersecurity measures increases. As the methods used by malicious actors evolve, staying updated with the latest threats and vulnerabilities becomes essential for organizations.

Key Takeaways

  • North Korean hackers are exploiting the CVE-2026-68820 Windows zero-day vulnerability.
  • The attacks target the defense and aerospace sectors in countries including France, Germany, Brazil, and India.
  • The malicious payloads utilize techniques such as DLL sideloading and exploitation of PDF viewers.
  • Organizations are advised to apply the August Patch Tuesday updates without delay.
  • Ongoing monitoring and scrutiny of unsolicited outreach are essential security practices.

Conclusion

The recent cyberattacks attributed to North Korean hackers underscore a significant security threat. The exploitation of the zero-day vulnerability CVE-2026-68820 emphasizes a pressing need for vigilance among cybersecurity professionals, particularly in critical sectors like defense and aerospace. As the Lazarus Group continues to adapt their tactics, organizations must remain proactive in defending against such sophisticated threats.

Frequently Asked Questions

CVE-2026-68820 is a zero-day vulnerability in Windows' Ancillary Function Driver for WinSock that allows hackers to gain system privileges.
#Cybersecurity#North Korea#Windows CVE#Lazarus Group#Cyberattacks