Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Lazarus Group is exploiting a recently patched Windows zero-day, CVE-2026-68820, to deliver a new backdoor called Troy against defense and aerospace targets in France, Germany, Brazil, and India through Operation Dream Job. The campaign uses fake recruiter lures, trojanized PDF software, and compromised legitimate sites and servers to spread MISTPEN, ForestTiger, FudModule 3.1, and RelayShell while evading security controls. #LazarusGroup #OperationDreamJob #CVE-2026-68820 #Troy #MISTPEN #ForestTiger #FudModule31 #RelayShell #Enveil #AFDsys

Keypoints

  • Lazarus Group abused a Windows zero-day to deploy the Troy backdoor.
  • The attacks targeted defense and aerospace organizations in multiple countries.
  • Operation Dream Job used fake recruiter messages and trojanized PDF tools.
  • Two infection chains delivered MISTPEN, ForestTiger, and FudModule 3.1.
  • The campaign also used compromised WordPress, SharePoint, and Roundcube systems for C2.

Read More: https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html