← Back to blog

Lazarus Group Exploits Windows Zero-Day to Target Aerospace Firms

North Korea's Lazarus Group used a Windows zero-day to deploy a new backdoor. The campaign impacted defense sectors in multiple countries.

TL;DR

  • Lazarus exploited a newly patched Windows zero-day flaw.
  • A previously unseen backdoor was deployed to targeted systems.
  • Victims include defense and aerospace firms in France, Germany, Brazil, and India.
  • The operation is part of the ongoing 'Operation Dream Job' espionage campaign.
  • Organizations should patch immediately and monitor for suspicious network activity.

In a significant escalation, North Korea’s advanced persistent threat (APT) group Lazarus has been observed exploiting a zero-day vulnerability in Microsoft Windows. This attack enabled the group to gain SYSTEM-level access and deploy a previously unknown backdoor.

The campaign, dubbed 'Operation Dream Job' by Check Point Research, primarily targets organizations within the defense and aerospace industries across several nations including France, Germany, Brazil, and India. These attacks underscore the persistent threat posed by state-sponsored actors and highlight the critical importance of timely patching and proactive threat hunting.

Vulnerability and Exploitation Details

  • The exploited flaw is a now-patched Windows vulnerability that allowed privilege escalation to SYSTEM level.
  • Lazarus used spear-phishing tactics to initially compromise target environments before deploying the zero-day exploit.
  • Microsoft released a security advisory urging users to apply updates immediately to mitigate risk.

Backdoor Deployment and Impact

  • A never-before-seen backdoor was installed on compromised machines to maintain persistent access.
  • The malware enables data exfiltration, remote command execution, and lateral movement within networks.
  • Affected organizations span high-value sectors such as aerospace and national defense, suggesting strategic intelligence goals.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Lazarus Group Exploits Windows Zero-Day to Target Aerospace Firms — Agent Breach Blog | Agent Breach