Threat Intelligence

North Korean Hackers Exploited Windows Zero-Day to Plant New Backdoor

The Hacker News · 13 Aug 2026
Key Takeaway Apply Microsoft security patches as soon as they're released, since attackers often exploit unpatched vulnerabilities long after fixes become available.

Security researchers at Check Point have linked the North Korean state-sponsored hacking group Lazarus to the exploitation of a zero-day vulnerability in Microsoft Windows. The flaw, which has since been patched by Microsoft, allowed attackers to gain SYSTEM-level access — the highest level of control on a Windows machine — and install a new, previously undocumented backdoor.

The campaign targeted defense and aerospace organisations in France, Germany, Brazil, and India, and forms part of 'Operation Dream Job,' a long-running Lazarus espionage campaign that typically lures victims with fake job offers before delivering malicious payloads. By exploiting an unknown vulnerability before a fix was available, the attackers were able to bypass normal security defences and embed themselves deep within targeted systems.

While this specific campaign focused on large defense and aerospace companies, it highlights a broader risk for all businesses: attackers increasingly use zero-day flaws to gain privileged access before defenders even know a vulnerability exists. Once patches are released, unpatched systems remain vulnerable, making timely updates critical.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.