www.securityweek.com 8/12/2026, 9:11:09 AM · external

Lazarus uses fake job offers to exploit Windows CVE-2026-68820

Lazarus uses fake job offers to exploit Windows CVE-2026-68820
CyberSIXT Evidence Panel
Primary Source blog.checkpoint.com
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor

NORTH Korean hackers, attributed to the Lazarus Group, are exploiting a newly patched Windows zero-day vulnerability (CVE-2026-68820) to infiltrate systems, targeting the defense sector through fake job offers. This campaign, part of 'Operation Dream Job,' has been active since early 2026, affecting aerospace and aviation organizations in Europe and India. Victims are convinced to download malicious files disguised as job-related materials.

The attackers employ DLL sideloading to deploy the Mistpen malware and use a decoy job description to mislead victims. The security community, particularly in affected sectors, is urged to monitor indicators of compromise and prioritize recent security patches to mitigate risks.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline