North Korean hackers linked to the Lazarus Group are abusing the newly patched Windows zero-day CVE-2026-68820 in fake job application lures to compromise defense, aerospace, and aviation targets. The campaign uses Mistpen, ForestTiger, Troy, SecurityPDF, and RelayShell to gain SYSTEM privileges, persist, and steal data through compromised web infrastructure. #LazarusGroup #CVE-2026-68820 #Mistpen #ForestTiger #Troy #SecurityPDF #RelayShell
Keypoints
- Lazarus Group is using fake recruiter messages to target job seekers.
- The campaign focuses on defense, aerospace, and aviation organizations in Europe, India, and other countries.
- A new Windows zero-day, CVE-2026-68820, is exploited to gain SYSTEM privileges.
- Attack chains deploy Mistpen, ForestTiger, SecurityPDF, and the Troy backdoor.
- Compromised Roundcube and CMS servers, plus RelayShell, support command-and-control activity.
Read More: https://www.securityweek.com/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks/