North Korean Hackers Exploit Windows Zero-Day Vulnerability
North Korean hackers have exploited a new Windows zero-day vulnerability, leading to cyberattacks on defense and aerospace sectors in several countries.

Recent Cyberattacks by North Korean Hackers
North Korean hackers are currently exploiting a newly patched Windows zero-day vulnerability, raising alarms among cybersecurity experts. According to Check Point, this vulnerability has enabled attackers from the notorious Lazarus Group APT to compromise systems worldwide. The ongoing attacks are part of a long-established campaign dubbed Operation Dream Job, which targets job seekers with counterfeit employment offers at reputable organizations.
The Vulnerability in Focus
The defect in question is a zero-day vulnerability in the Ancillary Function Driver for WinSock, tracked as CVE-2026-68820. This use-after-free vulnerability allows attackers to trigger a race condition to gain System privileges. Microsoft issued a patch for this vulnerability on August 11, 2026, during its Patch Tuesday updates. Following the patch, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to implement the patch within a two-week timeframe.
Attack Methodology
The hackers employ various tactics to compromise victims' systems. The infection typically begins with the delivery of a malicious payload disguised as an employment offer. This is facilitated through popular professional networks and direct messaging applications. Victims are misled into downloading a ZIP archive that contains a malicious Dynamic Link Library (DLL) along with a PDF viewer and encrypted payload designed to look like a legitimate PDF file.
DLL Sideloading and Initial Infection
In one infection chain, attackers leverage DLL sideloading to execute the Mistpen malware downloader directly in memory. While a decoy job description is presented on the screen, recon and persistence techniques are employed to explore system vulnerabilities.
Subsequent Exploits and Backdoor Deployments
Following the initial compromise, the attackers deploy ForestTiger, a backdoor associated with Lazarus, allowing further access and control over infected systems. Additionally, a separate infection path utilizes the trojanized PDF viewer named SecurityPDF, which executes the Troy backdoor directly in memory. This newly identified DLL implant enables 17 operator commands, facilitating extensive system manipulation including data exfiltration and shell access.
Targeted Sectors and Countries
| Targeted Sector | Countries Affected |
|---|---|
| Aerospace | France |
| Defense | Germany |
| Aviation | Brazil |
| Aerospace | India |
The fresh campaign has focused on the defense and aerospace sectors across multiple countries, particularly in Europe and India. As per Check Point, organizations in France, Germany, Brazil, and India have been primary targets of these malicious activities. The choice of sectors and regions reflects the strategic interests of the Lazarus Group, known for targeting industries relevant to national security.

Command and Control Infrastructure
In these attacks, the command-and-control (C&C) infrastructure includes compromised Roundcube webmail deployments and various content management system (CMS) platforms. Many of these platforms have been found vulnerable to the CVE-2025-49113, a remote code execution (RCE) vulnerability that has been exploited since June 2025. This dynamic allows attackers to maintain ongoing communication with infected endpoints via a PHP webshell known as RelayShell. Unlike standard backdoors, RelayShell operates more like a communication relay, transferring commands and responses through uncomplicated text files.
Recommendations for Security Teams
Given the current threat landscape incorporating a zero-day vulnerability and new backdoor capabilities, security teams in affected sectors must prioritize immediate responses. Check Point advises that organizations conduct thorough reviews of the indicators of compromise (IoCs) associated with these attacks. It’s crucial to implement the August Patch Tuesday updates and apply vigilance to unsolicited recruiting efforts, treating them with the same caution as unverified download requests.
Broader Implications of the Attacks
The implications of these cyberattacks highlight the vulnerabilities present not only in individual systems but also across entire sectors critical to national security. With enhanced targeting of industries involved in defense and aerospace, the need for robust cybersecurity measures increases. As the methods used by malicious actors evolve, staying updated with the latest threats and vulnerabilities becomes essential for organizations.
Key Takeaways
- North Korean hackers are exploiting the CVE-2026-68820 Windows zero-day vulnerability.
- The attacks target the defense and aerospace sectors in countries including France, Germany, Brazil, and India.
- The malicious payloads utilize techniques such as DLL sideloading and exploitation of PDF viewers.
- Organizations are advised to apply the August Patch Tuesday updates without delay.
- Ongoing monitoring and scrutiny of unsolicited outreach are essential security practices.
Conclusion
The recent cyberattacks attributed to North Korean hackers underscore a significant security threat. The exploitation of the zero-day vulnerability CVE-2026-68820 emphasizes a pressing need for vigilance among cybersecurity professionals, particularly in critical sectors like defense and aerospace. As the Lazarus Group continues to adapt their tactics, organizations must remain proactive in defending against such sophisticated threats.
Frequently Asked Questions
