Cookie Consent by Free Privacy Policy Generator

Lazarus group exploits Windows zero-day to target defence and aerospace sectors

The North Korean threat actor known as Lazarus Group has been linked to the exploitation of a Windows zero-day vulnerability as part of its ongoing Operation Dream Job campaign. The Hacker News reports that the flaw, which has since been patched by Microsoft, allowed attackers to gain SYSTEM-level access and deploy a previously unknown backdoor targeting defence and aerospace companies in France, Germany, Brazil and India. The campaign used social engineering tactics, including fake job offers, to lure targets into opening malicious files that exploited the vulnerability. Check Point Research, which identified the activity, notes that Lazarus continues to refine its techniques and target high-value sectors with strategic intelligence value.

Why this matters for UK organisations

This is a reminder that the defence, aerospace and advanced manufacturing sectors remain priority targets for sophisticated nation-state actors. Lazarus is known for its persistence, technical capability and willingness to exploit zero-day vulnerabilities to achieve its objectives. The use of social engineering, particularly fake recruitment approaches, reflects a broader pattern in which attackers combine technical exploits with human manipulation to gain initial access. This is especially relevant for organisations that employ individuals with security clearances, access to sensitive intellectual property or involvement in defence-related projects, as these individuals are often specifically targeted. The campaign also highlights the importance of ensuring that security awareness training reflects current threat actor techniques and that employees understand how to recognise and report suspicious approaches, particularly those that appear to come from recruiters or professional networking platforms.

What to review

Organisations in the defence, aerospace and advanced manufacturing sectors should review whether employees are aware of social engineering tactics, particularly fake recruitment approaches, and whether security awareness training reflects current threat actor techniques. This includes ensuring that employees understand how to recognise suspicious job offers, how to verify the legitimacy of recruitment approaches, and how to report suspicious activity to security teams. Organisations should also ensure that Windows systems are patched promptly, that endpoint detection and response tools are in place, and that monitoring is configured to detect unusual privilege escalation or lateral movement activity. For organisations working on sensitive projects, this is a reminder that threat actors are actively targeting individuals with access to valuable information, and that security must extend beyond technical controls to include awareness, reporting and incident response. This is also a prompt to review whether incident response plans include procedures for responding to targeted social engineering campaigns and whether security teams have the tools and visibility needed to detect and respond to sophisticated attacks.

Source: The Hacker News

News and blog posts
The National Cyber Security Centre has published new guidance recommending that...
UK charity CRM provider Beacon has confirmed that a compromised AWS access key...
Security researchers have identified a global exploitation campaign targeting...
The North Korean threat actor known as Lazarus Group has been linked to the...