Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek .
AI Analysis
Technical Summary
The vulnerability CVE-2026-68820 is a use-after-free flaw in Windows afd.sys that enables attackers to trigger a race condition and escalate privileges to System level. North Korean Lazarus Group has exploited this zero-day in a campaign targeting aerospace and defense organizations, primarily in Europe and India, since early 2026. Attackers use social engineering via fake job offers to deliver malicious payloads involving DLL sideloading and malware downloaders. The exploitation chain culminates in deploying the ForestTiger backdoor. Additionally, a trojanized PDF viewer named SecurityPDF is used to deploy the Troy backdoor in memory. The attackers' infrastructure includes compromised Roundcube webmail and CMS platforms vulnerable to CVE-2025-49113, hosting a PHP webshell called RelayShell for command relay. Microsoft patched the vulnerability on August 11, 2026, and CISA has mandated patching within two weeks for federal agencies.
Potential Impact
Successful exploitation allows attackers to gain full System privileges on affected Windows systems, enabling complete control over the victim machine. This facilitates deployment of persistent backdoors such as ForestTiger and Troy, enabling extensive espionage capabilities including file operations, shell access, process manipulation, and data exfiltration. The campaign targets sensitive sectors like defense and aerospace, potentially compromising critical intellectual property and operational security. The use of sophisticated infection chains and web-based command infrastructure increases stealth and persistence.
Mitigation Recommendations
Microsoft released an official patch for CVE-2026-68820 on August 11, 2026, as part of Patch Tuesday updates. Organizations, especially in defense, aerospace, and aviation sectors, should prioritize applying this update immediately. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog and urges federal agencies to patch within two weeks. Security teams should also scrutinize unsolicited recruitment communications and avoid downloading unverified payloads. Reviewing indicators of compromise related to ForestTiger, Troy backdoors, and associated infrastructure is recommended. No vendor advisory indicates that no action is required; patching is the primary mitigation.
Affected Countries
France, Germany, Brazil, India
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
Description
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-68820 is a use-after-free flaw in Windows afd.sys that enables attackers to trigger a race condition and escalate privileges to System level. North Korean Lazarus Group has exploited this zero-day in a campaign targeting aerospace and defense organizations, primarily in Europe and India, since early 2026. Attackers use social engineering via fake job offers to deliver malicious payloads involving DLL sideloading and malware downloaders. The exploitation chain culminates in deploying the ForestTiger backdoor. Additionally, a trojanized PDF viewer named SecurityPDF is used to deploy the Troy backdoor in memory. The attackers' infrastructure includes compromised Roundcube webmail and CMS platforms vulnerable to CVE-2025-49113, hosting a PHP webshell called RelayShell for command relay. Microsoft patched the vulnerability on August 11, 2026, and CISA has mandated patching within two weeks for federal agencies.
Potential Impact
Successful exploitation allows attackers to gain full System privileges on affected Windows systems, enabling complete control over the victim machine. This facilitates deployment of persistent backdoors such as ForestTiger and Troy, enabling extensive espionage capabilities including file operations, shell access, process manipulation, and data exfiltration. The campaign targets sensitive sectors like defense and aerospace, potentially compromising critical intellectual property and operational security. The use of sophisticated infection chains and web-based command infrastructure increases stealth and persistence.
Defensive Guidance
Microsoft released an official patch for CVE-2026-68820 on August 11, 2026, as part of Patch Tuesday updates. Organizations, especially in defense, aerospace, and aviation sectors, should prioritize applying this update immediately. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog and urges federal agencies to patch within two weeks. Security teams should also scrutinize unsolicited recruitment communications and avoid downloading unverified payloads. Reviewing indicators of compromise related to ForestTiger, Troy backdoors, and associated infrastructure is recommended. No vendor advisory indicates that no action is required; patching is the primary mitigation.
Technical Details
- Classification
- {"confidence":0.7,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks/","fetched":true,"fetchedAt":"2026-08-12T08:56:13.355Z","wordCount":1190}
Threat ID: 6a7c352dbf8831d5394902b2
Added to database: 08/12/2026, 08:56:13 UTC
Last enriched: 08/12/2026, 08:56:22 UTC
Last updated: 09/25/2026, 04:18:36 UTC
Views: 317
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.