THE Lazarus Group, linked to North Korea, executed a new malware campaign utilizing a post-quantum key exchange to negotiate its command channel and deploy a Windows zero-day exploit against defense and aerospace firms in Europe and India. The exploitation targeted a specific vulnerability (CVE-2026-68820) that was promptly reported to Microsoft.
The campaign, part of Operation Dream Job, involved phishing tactics with fake job offers aimed at defense employees, using sophisticated delivery methods including a downloader called MISTPEN and an undocumented PHP webshell for communication. The group employed a complex encryption scheme and deployed the FudModule kernel rootkit, enhancing their stealth and persistence.