news.mlab.sh
Back to the feed
threat-intel

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

High
Image: The Hacker News
Summary

The Lazarus Group, a North Korean threat actor, is exploiting a newly patched zero-day vulnerability in Microsoft Windows' AFD.sys driver to gain SYSTEM access and deploy a backdoor called Troy. They are leveraging a sophisticated social engineering campaign – Operation Dream Job – to trick employees at defense and aerospace companies in France, Germany, Brazil, and India into installing a trojanized PDF viewer and ultimately executing the backdoor. The campaign utilizes hijacked legitimate websites impersonating Enveil to distribute the malicious PDF viewer and employs a layered attack chain, including a new kernel-mode rootkit, to evade detection and maintain persistent access.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.