Jessica Entwistle
August 13 2026
The North Korean threat actor known as Lazarus Group has exploited a Windows zero-day vulnerability to deliver a previously unseen backdoor as part of Operation Dream Job, a long-running espionage campaign targeting defence and aerospace companies. The Hacker News reports that Check Point Research identified the activity affecting organisations across France, Germany, Brazil and India. The zero-day, which has since been patched by Microsoft, allowed the attackers to gain SYSTEM-level access on compromised Windows machines. Infosecurity Magazine notes that the malware used post-quantum key exchange mechanisms to protect delivery of the zero-day exploit, demonstrating sophisticated operational security by the attackers.
Operation Dream Job is a well-established Lazarus campaign that uses fake recruitment approaches to deliver malware to individuals working in defence, aerospace and technology sectors. The use of a Windows zero-day and post-quantum cryptography shows continued investment in sophisticated attack techniques by a persistent and well-resourced threat actor. For UK organisations in targeted sectors, this activity reinforces the importance of endpoint detection, user awareness of social engineering techniques and the operational security challenges posed by nation-state actors who combine technical sophistication with patient, targeted approaches. The recruitment-themed social engineering is particularly effective because it exploits professional ambition and curiosity, and targets individuals who may have access to sensitive systems, intellectual property or operational information. The use of SYSTEM-level access indicates that the attackers are seeking deep, persistent access to compromised environments rather than opportunistic data theft.
For UK businesses in defence, aerospace, technology and related supply chains, this is a prompt to review whether endpoint detection capabilities would identify unusual privilege escalation or SYSTEM-level access, and whether employees are aware of recruitment-themed social engineering techniques. Consider whether security awareness programmes specifically address the risks of unsolicited recruitment contact, particularly for individuals in sensitive roles, and whether employees understand how to report suspicious recruitment approaches. Review whether endpoint detection and response tools are configured to alert on unusual privilege escalation, lateral movement or persistence mechanisms, and whether incident response plans account for sophisticated, persistent threat actors who may maintain access for extended periods. Ensure that supply chain partners and contractors working on sensitive projects are also aware of these risks and have appropriate security controls in place.
Source: The Hacker News