North Korean Hackers Exploit Windows Zero-Day Vulnerability, Latest Cybersecurity Threat

www.news4hackers.com-north-korean-hackers-exploit-windows-zero-day-vulnerability-latest-cybersecurity-threat-north-korean-hackers-exploit-windows-zero-day-vulnerability-latest-cybersecurity-threat

A recently addressed Windows zero-day vulnerability has been leveraged by North Korean cyber actors to compromise systems, according to security researchers.

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

The attacks, linked to the Lazarus Group advanced persistent threat (APT), are part of an ongoing operation targeting job seekers with fabricated employment opportunities. This campaign, active since early 2026, has focused on defense sector entities, particularly in aerospace and aviation industries across Europe and India.

The Attack Methodology

Attackers initiated contact with potential victims through professional networking platforms or direct messaging services, posing as recruiters. One method involved delivering a malicious archive containing a PDF viewer, a compromised dynamic-link library (DLL), and an encrypted payload disguised as a PDF file. The DLL sideloading technique was used to execute Mistpen malware, a component of the broader attack chain.

According to security researchers, following initial compromise, the attackers conducted reconnaissance, established persistence, and exploited an unpatched vulnerability in the Ancillary Function Driver for WinSock (afd.sys). This flaw, designated CVE-2026-68820, is a use-after-free vulnerability that enables attackers to trigger a race condition and escalate privileges to system level.

The Vulnerability Exploited

Microsoft resolved the issue in its August 2026 Patch Tuesday updates and included it in the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to apply the patch within two weeks.

The Second Infection Vector

A second infection vector involved a compromised PDF viewer called SecurityPDF, which scans opened documents for a hidden marker to execute the Troy backdoor in memory. Troy is a novel DLL implant capable of executing 17 operator commands, including file enumeration and data exfiltration.

The Command-and-Control Infrastructure

The command-and-control (C&C) infrastructure utilized in these attacks relies on compromised Roundcube webmail systems and content management platforms vulnerable to CVE-2025-49113, a remote code execution flaw exploited since June 2025. Researchers identified RelayShell, a previously undocumented PHP webshell, as part of the infrastructure. This tool functions as a communication relay between infected endpoints and attackers, exchanging commands and responses via text files to mimic legitimate traffic.

Targeted Organizations

Targeted organizations include defense, aerospace, and aviation entities in France, Germany, Brazil, and India. Security experts emphasize the urgency of applying the August 2026 patch, reviewing indicators of compromise, and maintaining heightened vigilance against unsolicited recruitment communications.

Patch and Mitigation

The combination of a patched zero-day, a modular backdoor, and web-based infrastructure underscores the sophistication of the threat. The campaign highlights the evolving tactics of state-sponsored actors, who continue to exploit both software vulnerabilities and human trust mechanisms. Organizations in high-risk sectors are advised to prioritize patch management, monitor for anomalous network activity, and conduct regular security audits to mitigate potential threats.

Conclusion

Organizations in high-risk sectors are advised to prioritize patch management, monitor for anomalous network activity, and conduct regular security audits to mitigate potential threats.



About Author

en_USEnglish