NORTH Korean hackers, attributed to the Lazarus Group, are exploiting a newly patched Windows zero-day vulnerability (CVE-2026-68820) to infiltrate systems, targeting the defense sector through fake job offers. This campaign, part of 'Operation Dream Job,' has been active since early 2026, affecting aerospace and aviation organizations in Europe and India. Victims are convinced to download malicious files disguised as job-related materials.
The attackers employ DLL sideloading to deploy the Mistpen malware and use a decoy job description to mislead victims. The security community, particularly in affected sectors, is urged to monitor indicators of compromise and prioritize recent security patches to mitigate risks.