Lazarus Hits Windows Zero-Day to Plant a Backdoor in Defense Firms

·
Listen to this article~5 min
Lazarus Hits Windows Zero-Day to Plant a Backdoor in Defense Firms

Lazarus Group exploits a Windows zero-day to deploy a new backdoor in defense and aerospace firms across Europe and beyond. Learn how Operation Dream Job works and how to stay protected.

The Lazarus Group, a North Korean state-sponsored hacking team, has been caught exploiting a freshly patched Windows vulnerability to slip a brand-new backdoor into defense and aerospace companies. The targets spanned France, Germany, Brazil, and India, and the whole operation is part of a long-running campaign called Operation Dream Job. Security researchers at Check Point Research (CPR) flagged the activity, noting that Lazarus moved fast to weaponize the flaw before many organizations had time to patch. That's a classic move from this group—they're known for turning zero-days into working exploits within days, sometimes hours, of a patch release. ### What's New About This Attack? The zero-day itself is interesting, but the real story is the backdoor. This isn't a repurposed tool from Lazarus's old arsenal. It's a completely new piece of malware, purpose-built for this campaign. That tells us the group is investing heavily in fresh capabilities, which is a bit unnerving for anyone in the defense or aerospace space. According to CPR, the backdoor is designed to give the attackers SYSTEM-level access on compromised Windows machines. That's the highest privilege level on the operating system, meaning they can read files, install drivers, disable security tools, and move laterally across networks without raising many red flags. ### Operation Dream Job: A Familiar Name, A New Twist If the name Operation Dream Job rings a bell, that's because it's been around for years. The campaign typically works like this: attackers pose as recruiters or headhunters, sending fake job offers to employees at target companies. The lure is a malicious document or link that, once clicked, triggers the exploit chain. What's different this time is the combination of the zero-day and the new backdoor. Previous versions of Dream Job relied on known vulnerabilities or phishing lures. Now, Lazarus is stacking a zero-day exploit with fresh malware, which makes the whole operation more dangerous and harder to detect. ### Who's in the Crosshairs? The victims are spread across four countries, but the common thread is the industry: defense and aerospace. These are high-value targets because they hold sensitive intellectual property, military tech specs, and supply chain data. If Lazarus gets into one of these networks, they could potentially steal designs for weapons systems, radar tech, or even satellite components. Check Point Research didn't name the specific companies, but they did note that the attacks were highly targeted. This wasn't a spray-and-pray campaign. Each victim was likely researched in advance, with tailored lures to match their role and interests. ### Why This Matters for You If you work in defense, aerospace, or any adjacent industry, this should be a wake-up call. Even if you're not in those sectors, the takeaway is broader: zero-day exploits are becoming more common, and threat actors are getting faster at weaponizing them. Here's what you can do to reduce your risk: - **Patch immediately.** The vulnerability is already patched by Microsoft, but many organizations lag by weeks or months. Set up automated patching where possible. - **Watch for fake recruiters.** If you receive an unsolicited job offer with an attachment or link, verify the sender through a separate channel before clicking anything. - **Monitor for SYSTEM-level anomalies.** If your security team sees unusual privilege escalations, investigate them right away. - **Use browser isolation or antidetect tools.** For high-risk users, isolating browsing activity can block exploit chains before they reach the OS. ### The Bottom Line Lazarus Group isn't slowing down. They're using zero-days, new backdoors, and social engineering to hit some of the most sensitive industries in the world. The best defense is still the basics: patch fast, stay skeptical of unsolicited messages, and keep a close eye on privileged accounts. If you're responsible for security in a defense or aerospace firm, consider this a direct warning. The attackers are already inside someone's network—make sure it's not yours.