
North Korean hacking organization Lazarus Group has orchestrated a major attack on a dangerous flaw found within Microsoft's latest update, forcing the company behind Windows to issue an emergency patch in an ongoing cat and mouse chase against the cybercriminals.
It appears to be part of a wider multi-year effort known as Operation Dream Job, as per The Hacker News, where the Pyongyang-backed hacking group aims to offer fake jobs from leading American firms like Lockheed Martin and Enveil to individuals who are then targeted by malware on their devices.
This cybersecurity threat works by luring prospective and targeted professionals with attractive job offers through platforms like LinkedIn, and then tricking them into opening malicious PDFs or installing a trojanized PDF viewer, allowing the hackers to take kernel-level control of their devices.
Similar efforts from the Lazarus Group have been attempted for several years, with hackers able to gain a level of control that completely bypasses security systems and user inputs, and it's forced Microsoft into pushing an emergency patch to cover the issue.
Microsoft releases emergency patch to fix North Korean threat
Detailed in Microsoft's CVE-2026-68820 security vulnerability update released on August 11, the patch resolves an issue where the Windows Ancillary Function Driver for WinSock 'allowed an authorized attacker to elevate privileges locally'.
Advert

The tech giant detailed how attackers who successfully exploited this vulnerability "could gain system privileges," with user interaction not required in order to effectively hand the keys to your device over to the hackers.
Efforts identified as part of Operation Dream Job have been tracked all the way back to 2022, and it's likely that this emergency patch is unfortunately not the last the Microsoft will have to issue with attackers almost guaranteed to find more loopholes and exploits in the future.
Why is this attack so effective?
The effectiveness of this attack comes from the amount of potentially compromising or confidential information that hackers can receive by targeting key professionals, exposing secrets that could even potentially inform geopolitical tensions between the United States and North Korea.
It's incredibly difficult to spot these attacks before they take place too, with the infrastructure intentionally hidden to the point where even experts struggle to discern what's real and what's malicious.

"What makes this campaign so dangerous is not only the zero-day vulnerability," explained Sergey Shykevich, director of threat intelligence at Check Point Software, in a statement to The Hacker News, "but also how Lazarus wove legitimate, trusted infrastructure into every stage of the attack."
Shykevich continues to illustrate that the hackers "hid in plain sight, behind top-ranked search results, real vendor branding, and the reputation of organizations they had already compromised.
"When the website, the download, and the recruiter all appear authentic," he explained, "the old advice to 'spot the phishing link' is no longer easily applicable. Staying safe now means assuming the trust itself can be counterfeited: patch the moment updates land, verify software through official channels rather than search rankings, and extend zero-trust thinking to the legitimate-looking sites and partners we interact with every day."