Lazarus Group’s Operation Dream Job Exploits Zero-Day Vulnerability to Target Defense Sector in 2026 Cyberattacks

Published:

Lazarus Group’s Operation Dream Job Exploits Zero-Day Vulnerability to Target Defense Sector in 2026 Cyberattacks

In early 2026, a significant wave of cyberattacks emerged under the name Operation Dream Job, attributed to the infamous Lazarus Group, which is associated with North Korea. This campaign has primarily focused on organizations within the defense sector, particularly in Europe and India, employing advanced techniques to exploit vulnerabilities and gain unauthorized access to sensitive data.

The latest phase of this operation involves the distribution of a modified PDF viewer known as SecurityPDF. This tool is designed to execute malicious payloads embedded in specially crafted PDF documents. This development marks a notable shift in the group’s tactics, as they increasingly rely on impersonation websites and search engine optimization (SEO) strategies to enhance the credibility of their malicious applications, thus evading detection.

At the core of this campaign is the exploitation of a zero-day vulnerability identified as CVE-2026-68820 in the Microsoft AFD.sys driver. This vulnerability enables attackers to escalate privileges and disable endpoint detection and response (EDR) visibility. Following responsible disclosure by Check Point Research, Microsoft issued a patch for this vulnerability as part of their August Patch Tuesday updates.

The Infection Chain

The attack begins with targeted spear-phishing lures that present attractive job opportunities at well-known companies in the defense, aerospace, and aviation sectors. While the precise methods of approach remain unclear, previous campaigns suggest that attackers likely utilize professional networking platforms such as LinkedIn or direct messaging applications to impersonate recruiters.

Two distinct infection chains have been identified in this campaign:

Infection Chain 1: DLL Sideloading

In this chain, victims are deceived into downloading an encrypted ZIP archive containing a legitimate PDF viewer executable, a malicious DLL, and an encrypted payload. When the executable is launched, the malicious DLL is loaded via DLL sideloading, extracting and executing an embedded payload in memory. This payload, referred to as MISTPEN, functions as a lightweight downloader that retrieves additional modules from Microsoft OneDrive, facilitating further exploitation.

Infection Chain 2: Trojanized PDF Viewer

The second infection chain involves fraudulent job offers impersonating Enveil, a privacy-enhancing technology company. Victims are instructed to download an encrypted ZIP archive containing SecurityPDF and a malicious PDF file. The trojanized PDF viewer is engineered to extract and execute an encrypted payload when a specially crafted PDF is opened, leading to the deployment of the Troy backdoor, a newly identified modular remote access trojan.

Technical Insights into the Malware

The Troy backdoor supports a wide array of commands, enabling extensive remote access and post-exploitation capabilities. It establishes connections with multiple command-and-control (C2) servers, allowing attackers to maintain control over compromised systems. The design of the backdoor facilitates various operations, including file exfiltration, process management, and in-memory code delivery.

Additionally, attackers have utilized compromised Roundcube webmail servers to host RelayShell, a PHP webshell that serves as a communication relay between the threat actor and infected endpoints. This method allows attackers to blend malicious communications with legitimate network traffic, complicating detection efforts.

Victimology and Implications

The Operation Dream Job campaign has predominantly targeted organizations involved in military technologies, including surveillance sensors, drones, and robotics. The global reach of this campaign has extended to South America and Western Europe, with notable activity observed in countries such as France, Germany, and India.

As the Lazarus Group continues to refine its operational techniques, the implications for organizations in the defense sector are significant. The combination of sophisticated malware, zero-day exploitation, and the use of compromised infrastructure underscores the necessity for heightened vigilance and robust cybersecurity measures.

For further details, you can access the full report by Check Point Research here.


Published on 2026-08-15 03:19:00 • By the Editorial Desk

For ongoing coverage and breaking updates, visit our Latest News section.

Share post:

[tds_leads title_text="Subscribe" input_placeholder="Email address" btn_horiz_align="content-horiz-center" pp_checkbox="yes" pp_msg="SSd2ZSUyMHJlYWQlMjBhbmQlMjBhY2NlcHQlMjB0aGUlMjAlM0NhJTIwaHJlZiUzRCUyMiUyMyUyMiUzRVByaXZhY3klMjBQb2xpY3klM0MlMkZhJTNFLg==" f_title_font_family="653" f_title_font_size="eyJhbGwiOiIyNCIsInBvcnRyYWl0IjoiMjAiLCJsYW5kc2NhcGUiOiIyMiJ9" f_title_font_line_height="1" f_title_font_weight="700" f_title_font_spacing="-1" msg_composer="success" display="column" gap="10" input_padd="eyJhbGwiOiIxNXB4IDEwcHgiLCJsYW5kc2NhcGUiOiIxMnB4IDhweCIsInBvcnRyYWl0IjoiMTBweCA2cHgifQ==" input_border="1" btn_text="I want in" btn_tdicon="tdc-font-tdmp tdc-font-tdmp-arrow-right" btn_icon_size="eyJhbGwiOiIxOSIsImxhbmRzY2FwZSI6IjE3IiwicG9ydHJhaXQiOiIxNSJ9" btn_icon_space="eyJhbGwiOiI1IiwicG9ydHJhaXQiOiIzIn0=" btn_radius="3" input_radius="3" f_msg_font_family="653" f_msg_font_size="eyJhbGwiOiIxMyIsInBvcnRyYWl0IjoiMTIifQ==" f_msg_font_weight="600" f_msg_font_line_height="1.4" f_input_font_family="653" f_input_font_size="eyJhbGwiOiIxNCIsImxhbmRzY2FwZSI6IjEzIiwicG9ydHJhaXQiOiIxMiJ9" f_input_font_line_height="1.2" f_btn_font_family="653" f_input_font_weight="500" f_btn_font_size="eyJhbGwiOiIxMyIsImxhbmRzY2FwZSI6IjEyIiwicG9ydHJhaXQiOiIxMSJ9" f_btn_font_line_height="1.2" f_btn_font_weight="700" f_pp_font_family="653" f_pp_font_size="eyJhbGwiOiIxMyIsImxhbmRzY2FwZSI6IjEyIiwicG9ydHJhaXQiOiIxMSJ9" f_pp_font_line_height="1.2" pp_check_color="#000000" pp_check_color_a="#ec3535" pp_check_color_a_h="#c11f1f" f_btn_font_transform="uppercase" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjQwIiwiZGlzcGxheSI6IiJ9LCJsYW5kc2NhcGUiOnsibWFyZ2luLWJvdHRvbSI6IjM1IiwiZGlzcGxheSI6IiJ9LCJsYW5kc2NhcGVfbWF4X3dpZHRoIjoxMTQwLCJsYW5kc2NhcGVfbWluX3dpZHRoIjoxMDE5LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" msg_succ_radius="2" btn_bg="#ec3535" btn_bg_h="#c11f1f" title_space="eyJwb3J0cmFpdCI6IjEyIiwibGFuZHNjYXBlIjoiMTQiLCJhbGwiOiIxOCJ9" msg_space="eyJsYW5kc2NhcGUiOiIwIDAgMTJweCJ9" btn_padd="eyJsYW5kc2NhcGUiOiIxMiIsInBvcnRyYWl0IjoiMTBweCJ9" msg_padd="eyJwb3J0cmFpdCI6IjZweCAxMHB4In0="]

Popular

More like this
Related

Bank of England governor calls for rigorous AI testing before regulation

The Governor of the Bank of England, Andrew Bailey, has emphasised the need for "rigorous" testing of artificial intelligence (AI) before implementing regulations. In his inaugural article for Substack, Bailey stated that while the risks associated with AI are "real…

Eleven Emirati AI experts engage with Canadian institutions to enhance responsible AI applications

Eleven Emirati artificial intelligence experts from the National Experts Programme’s Artificial Intelligence track (NEP-AI) are currently engaging with leading Canadian institutions to explore the translation of advanced AI research into responsible applications. This international study visit, which commenced on Monday…

Kaspersky uncovers phishing campaign impersonating Zoom and Docusign targeting corporate emails

Kaspersky has identified an ongoing phishing campaign that impersonates official emails from Zoom and Docusign, targeting corporate accounts across various regions, including the Middle East, Latin America, and Western Europe. This revelation highlights the persistence of traditional phishing tactics, even…

June Oven’s app and cloud services shut down, leaving users with unsupported devices

June Oven's app and cloud services have been shut down, leaving users with unsupported devices, according to a report by The Verge. The June Oven, a smart cooking appliance developed by a team of former Apple engineers, was known for…