Lazarus exploits Windows zero-day in defense sector espionage
North Korean state hackers deployed novel backdoor against aerospace and defense firms in France, Germany, Brazil, and India using unpatched Windows flaw.
The Lazarus Group exploited a previously unknown Windows vulnerability to deploy a new backdoor against defense and aerospace contractors across four countries, according to Check Point Research. The zero-day flaw, now patched by Microsoft, allowed the attackers to escalate privileges to SYSTEM level—the highest permission tier in Windows environments.
The intrusions form part of Operation Dream Job, a multi-year Lazarus campaign that uses fake recruitment offers to compromise targets. Check Point attributed the activity to North Korea's Reconnaissance General Bureau, the intelligence agency directing Lazarus operations. The newly identified backdoor has not been documented in prior threat reporting.
Targeted organizations span France, Germany, Brazil, and India, with a concentration in defense manufacturing and aerospace engineering. The timing coincides with heightened North Korean interest in missile guidance systems and satellite technology, though Check Point did not specify which data the attackers exfiltrated.
- 01Defense contractors in four countries face active espionage from state-backed intrusion set
- 02Windows privilege escalation zero-days remain viable entry points for advanced persistent threats
- 03Supply chain partners to targeted aerospace firms should assume secondary compromise risk
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.