
Lazarus Group Exploits Windows Zero-Day to Deploy Backdoor Worldwide
North Korea’s Lazarus Group exploited a Windows zero-day (CVE-2026-68820) to gain SYSTEM privileges and install a backdoor named Troy as part of Operation Dream Job, targeting defense and aerospace firms in France, Germany, Brazil and India. The campaign blends social engineering (fake LinkedIn recruiters) with a trojanized SecurityPDF viewer to trigger a DLL side-loading chain, dropping the MISTPEN downloader and ForestTiger/ScoringMathTea for remote access, while hijacking compromised WordPress/SharePoint/Roundcube infrastructure for C2 via Microsoft Graph API/OneDrive and using AFD.sys privilege escalation to stay hidden.