North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
Brief
Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls.
Check Point Research has uncovered a new wave of Operation Dream Job , the long-running North Korean campaign that lures defense and aerospace professionals with convincing fake job offers.
This iteration is more dangerous than previous versions: it includes a previously unknown Windows vulnerability now patched as CVE-2026-68820 , a newly documented backdoor called Troy, and command infrastructure built almost entirely from legitimate servers the attackers didn’t build, they hijacked them. Targets confirmed in France, Germany, Brazil, and India.
“The attackers used a previously unknown vulnerability in Windows (CVE-2026-68820) to gain full control of infected computers and evade EDR visibility.
