← Back to feed
DFIREmerging1 sourceAug 13, 2026 · 10:13via AboutDFIR

Infosec News Nuggets — August 13, 2026

Brief

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

North Korea’s Lazarus Group exploited a Windows zero-day in the AFD. sys driver as part of a fresh wave of its long-running Dream Job campaign, targeting defense and aerospace firms in France, Germany, Brazil, and India with fake recruiter outreach on LinkedIn.

Victims were lured into opening a trojanized PDF viewer or a malicious archive that deployed a new backdoor called Troy, while a companion downloader used the flaw to gain SYSTEM privileges and load an updated version of the FudModule rootkit capable of tampering with Windows Smart App Control.

The campaign hijacked compromised WordPress, SharePoint, and Roundcube servers for command-and-control traffic to blend in with legitimate web activity, and the exploited flaw has since been patched in Microsoft’s August update.

Read more on AboutDFIR