Lazarus Group Exploits Windows Zero-Day in Operation Dream Job
The Lazarus group, linked to North Korea, is actively exploiting a Windows zero-day vulnerability as part of Operation Dream Job, a long-running campaign targeting the defense sector with fake job offers. This campaign uses trojanized PDF software to gain initial access. The attacks are primarily aimed at the defense sector, with decoy documents including job descriptions from well-known companies like Lockheed Martin. Organizations are advised to prioritize patching and enhance defenses against Lazarus's tactics.