{"id":17660,"date":"2026-08-12T08:48:09","date_gmt":"2026-08-12T08:48:09","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17660"},"modified":"2026-08-12T08:48:09","modified_gmt":"2026-08-12T08:48:09","slug":"contemporary-home-windows-zero-day-exploited-in-north-korean-cyberattacks","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17660","title":{"rendered":"Contemporary Home windows Zero-Day Exploited in North Korean Cyberattacks"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\"><strong>North Korean hackers have been exploiting a newly patched Home windows zero-day vulnerability to take over victims\u2019 techniques, Test Level stories.<\/strong><\/p>\n<p class=\"wp-block-paragraph\">Attributed to the notorious <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/topics\/Lazarus\/\">Lazarus Group<\/a> APT, the assaults symbolize a continuation of the long-running <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/north-korea-apt-lazarus-targeting-chemical-sector\/\">Operation Dream Job<\/a> marketing campaign focusing on job seekers with faux work alternatives at well-known firms. North Korean hackers have been mounting <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/north-korean-hackers-target-open-source-developers-in-supply-chain-attacks\/\">faux job assault<\/a> variations usually.<\/p>\n<p class=\"wp-block-paragraph\">Lively since early 2026, the brand new marketing campaign has been focusing on the protection sector throughout a number of international locations, primarily aerospace and aviation organizations in Europe and India, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blog.checkpoint.com\/research\/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit\/\">Test Level says<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Posing as recruiters, the attackers have contacted potential victims via widespread skilled platforms or direct messaging functions and satisfied them to obtain a malicious payload.<\/p>\n<p class=\"wp-block-paragraph\">As a part of one an infection chain, an archive containing a PDF viewer, a malicious DLL, and an encrypted payload posing as a PDF file is served to the sufferer, and DLL sideloading is used to execute the Mistpen malware downloader in reminiscence whereas a decoy job description is proven on the display screen.<\/p>\n<p class=\"wp-block-paragraph\">The an infection chain continues with reconnaissance, persistence, and the exploitation of a beforehand unknown vulnerability in Home windows\u2019 Ancillary Perform Driver for WinSock (afd.sys), adopted by the deployment of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/north-korean-hackers-exploiting-recent-teamcity-vulnerability\/\">ForestTiger<\/a>, a identified Lazarus backdoor.<\/p>\n<div class=\"zox-post-ad-wrap\"><span class=\"zox-ad-label\">Commercial. Scroll to proceed studying.<\/span><\/div>\n<p class=\"wp-block-paragraph\">The afd.sys zero-day, now tracked as CVE-2026-68820, is a use-after-free subject that enables attackers to set off a race situation and achieve System privileges.<\/p>\n<p class=\"wp-block-paragraph\">On August 11, Microsoft fastened the vulnerability as a part of its <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day\/\">Patch Tuesday updates<\/a>, and the US cybersecurity company CISA added it to its Recognized Exploited Vulnerabilities (<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\">KEV<\/a>) catalog, urging federal businesses to patch it throughout the subsequent two weeks.<\/p>\n<p class=\"wp-block-paragraph\">In keeping with Test Level, a second an infection chain directs customers to the trojanized PDF viewer SecurityPDF, which searches for a hidden marker in any PDF file opened on the system to execute the Troy backdoor straight in reminiscence.<\/p>\n<p class=\"wp-block-paragraph\">Troy is a brand new DLL implant that helps 17 operator instructions, together with file enumeration\/obtain\/add, knowledge exfiltration, shell entry, course of termination, and DLL injection.<\/p>\n<p class=\"wp-block-paragraph\">The command-and-control (C&amp;C) infrastructure noticed in these assaults contains compromised Roundcube webmail deployments and CMS platforms, many susceptible to CVE-2025-49113, a distant code execution (RCE) flaw that has been <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/exploited-vulnerability-impacts-over-80000-roundcube-servers\/\">exploited since June 2025<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThese servers are contaminated with RelayShell, a beforehand undocumented PHP webshell that capabilities much less like a traditional backdoor and extra as a communication relay between contaminated endpoints and the operator, exchanging instructions and responses via easy textual content recordsdata,\u201d Test Level says.<\/p>\n<p class=\"wp-block-paragraph\">The cybersecurity agency says that protection, aerospace, and aviation organizations in France, Germany, Brazil, and India have been focused within the contemporary marketing campaign.<\/p>\n<p class=\"wp-block-paragraph\">\u201cGiven the mix of a zero-day vulnerability that now has a patch, a brand new modular backdoor, and web-based infrastructure designed to resemble respectable site visitors, safety groups in these sectors ought to prioritize the August Patch Tuesday replace, assessment the indications of compromise, and apply the identical degree of scrutiny to unsolicited recruiting outreach that they might apply to any unverified obtain request,\u201d Test Level notes.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Associated:<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/new-jersey-alabama-join-states-targeted-in-water-cyberattacks\/\">New Jersey, Alabama Be a part of States Focused in Water Cyberattacks<\/a><\/p>\n<p class=\"wp-block-paragraph\"><strong>Associated:<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/novel-private-apn-pivot-let-hackers-sabotage-second-polish-energy-facility\/\">Novel Personal APN Pivot Let Hackers Sabotage Second Polish Vitality Facility<\/a><\/p>\n<p class=\"wp-block-paragraph\"><strong>Associated:<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/us-allies-warn-of-russian-cyberattacks-targeting-critical-infrastructure-routers\/\">US, Allies Warn of Russian Cyberattacks Focusing on Important Infrastructure Routers<\/a><\/p>\n<p class=\"wp-block-paragraph\"><strong>Associated:<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/china-india-linked-hackers-both-targeted-same-pakistani-police-force\/\">China, India-Linked Hackers Each Focused Identical Pakistani Police Pressure<\/a><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>North Korean hackers have been exploiting a newly patched Home windows zero-day vulnerability to take over victims\u2019 techniques, Test Level stories. Attributed to the notorious Lazarus Group APT, the assaults symbolize a continuation of the long-running Operation Dream Job marketing campaign focusing on job seekers with faux work alternatives at well-known firms. North Korean hackers [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17662,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[2442,1994,3138,4714,4713,1059,4218],"class_list":["post-17660","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cyberattacks","tag-exploited","tag-fresh","tag-korean","tag-north","tag-windows","tag-zeroday"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17660","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17660"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17660\/revisions"}],"predecessor-version":[{"id":17661,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17660\/revisions\/17661"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17662"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17660"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-12 10:55:02 UTC -->