North Korean Hackers Exploited Windows Zero-Day to Plant New Backdoor
Security researchers at Check Point have linked the North Korean state-sponsored hacking group Lazarus to the exploitation of a zero-day vulnerability in Microsoft Windows. The flaw, which has since been patched by Microsoft, allowed attackers to gain SYSTEM-level access — the highest level of control on a Windows machine — and install a new, previously undocumented backdoor.
The campaign targeted defense and aerospace organisations in France, Germany, Brazil, and India, and forms part of 'Operation Dream Job,' a long-running Lazarus espionage campaign that typically lures victims with fake job offers before delivering malicious payloads. By exploiting an unknown vulnerability before a fix was available, the attackers were able to bypass normal security defences and embed themselves deep within targeted systems.
While this specific campaign focused on large defense and aerospace companies, it highlights a broader risk for all businesses: attackers increasingly use zero-day flaws to gain privileged access before defenders even know a vulnerability exists. Once patches are released, unpatched systems remain vulnerable, making timely updates critical.