Lazarus exploits Windows zero-day to target aerospace firms

North Korean-linked Lazarus Group used a patched Windows zero-day (CVE-2026-68820) and fake job offers to gain SYSTEM access and deploy backdoors in defense organizations.
Researchers at Check Point reported that North Korean-linked Lazarus Group exploited a Windows zero-day tracked as CVE-2026-68820 in a campaign active since early 2026. The attacks focused on defense-related aerospace and aviation organizations in France, Germany, India and Brazil. Microsoft released a patch for the flaw on August 11, and the U.S. Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities catalog with a two-week mitigation recommendation for federal agencies.
The attackers contacted potential targets on professional platforms and messaging apps, posing as recruiters and sharing archives that appeared to contain job materials. One infection chain delivered an archive with a PDF viewer, a malicious DLL and an encrypted file disguised as a PDF. The malicious DLL was sideloaded to run a downloader called Mistpen in memory while a decoy job description remained visible to the user.
After establishing a foothold and performing reconnaissance, operators exploited a use-after-free flaw in Windows’ Ancillary Function Driver for WinSock (afd.sys). The vulnerability allowed a race condition that elevated privileges to SYSTEM, permitting deployment of the ForestTiger backdoor.
A second infection route used a trojanized PDF viewer named SecurityPDF. That program scanned opened PDFs for a hidden marker and, when found, executed a new DLL implant called Troy directly in memory. Check Point described Troy as a modular implant supporting 17 operator commands, including file listing, download and upload, data exfiltration, interactive shell access, process termination and DLL injection.
Command-and-control infrastructure observed in the campaign included compromised Roundcube webmail instances and content-management systems. Many of those servers were vulnerable to CVE-2025-49113, a remote code execution flaw that has been exploited since June 2025. The researchers found a previously undocumented PHP webshell on those servers, labeled RelayShell, which relays commands and responses between infected endpoints and operators using simple text files.
Check Point warned: “Given the combination of a zero-day vulnerability that now has a patch, a new modular backdoor, and web-based infrastructure designed to resemble legitimate traffic, security teams in these sectors should prioritize the August Patch Tuesday update, review the indicators of compromise, and apply the same level of scrutiny to unsolicited recruiting outreach that they would apply to any unverified download request.”
Check Point also noted that observed tools and infrastructure-Mistpen, ForestTiger, Troy and RelayShell-are consistent with activity previously attributed to the Lazarus Group. The firm recommends applying Microsoft’s August patches, scanning endpoint telemetry and logs for signs of DLL sideloading or in-memory execution, and hardening webmail and CMS installations, including patches for CVE-2025-49113.








