Lazarus Group Strikes Again: Fake Job Offers, Real Zero-Days — India in the Crosshairs
North Korea's state-sponsored Lazarus Group is back in the headlines — and this time, the campaign hits closer to home for Indian defense-sector professionals.
What Happened
Security researchers at Check Point have attributed a new wave of attacks to Lazarus Group, part of their long-running "Operation Dream Job" campaign. The group is exploiting a freshly patched Windows zero-day vulnerability — CVE-2026-68820 — to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.
Social Engineering First — Attackers pose as recruiters from well-known defense firms like Lockheed Martin, sending fake but convincing job offers to professionals in the sector.
Zero-Day Exploitation — Once a target engages, the attackers exploit a privilege escalation flaw in AFD.sys (Windows Ancillary Function Driver for WinSock) — CVSS 7.0 — to gain SYSTEM-level access.
Backdoor Deployment — A custom, previously unseen backdoor is then installed for long-term espionage access.
The vulnerability was patched as part of Microsoft's August 2026 Patch Tuesday, which addressed 421 CVEs total — including one actively exploited zero-day and two publicly disclosed ones.
Why This Matters for India
India being named alongside France, Germany, and Brazil as a target signals that Indian defense and aerospace organizations are squarely in scope for nation-state APT activity. This isn't a random opportunistic attack — it's a targeted, resourced campaign.
Key Takeaways for Defenders
Patch immediately — if you haven't applied August 2026 updates, do it now.
Train your people — the strongest technical stack still fails if an employee clicks a convincing fake job offer.
Verify recruiter outreach through official channels before engaging with any "opportunity" that asks you to download files or click links.
Monitor for privilege escalation attempts on endpoint systems, especially around AFD.sys-related activity.
Final Thought
Nation-state actors like Lazarus Group don't need to break through hardened infrastructure when a well-crafted fake job offer does the job for them. Social engineering + zero-day chaining remains one of the most effective attack combos in 2026 — and defense sector professionals need to stay sharp.
— Pramod Jogdand, PremLabs Security
Learn • Build • Secure • Share
Comments
Post a Comment