Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The Lazarus Group, a North Korean threat actor, is exploiting a newly patched zero-day vulnerability in Microsoft Windows' AFD.sys driver to gain SYSTEM access and deploy a backdoor called Troy. They are leveraging a sophisticated social engineering campaign – Operation Dream Job – to trick employees at defense and aerospace companies in France, Germany, Brazil, and India into installing a trojanized PDF viewer and ultimately executing the backdoor. The campaign utilizes hijacked legitimate websites impersonating Enveil to distribute the malicious PDF viewer and employs a layered attack chain, including a new kernel-mode rootkit, to evade detection and maintain persistent access.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
