Lazarus Group’s Operation Dream Job Exploits Zero-Day Vulnerability to Target Defense Sector in 2026 Cyberattacks

Published:

Lazarus Group’s Operation Dream Job Exploits Zero-Day Vulnerability to Target Defense Sector in 2026 Cyberattacks

In early 2026, a significant wave of cyberattacks emerged under the name Operation Dream Job, attributed to the infamous Lazarus Group, which is associated with North Korea. This campaign has primarily focused on organizations within the defense sector, particularly in Europe and India, employing advanced techniques to exploit vulnerabilities and gain unauthorized access to sensitive data.

The latest phase of this operation involves the distribution of a modified PDF viewer known as SecurityPDF. This tool is designed to execute malicious payloads embedded in specially crafted PDF documents. This development marks a notable shift in the group’s tactics, as they increasingly rely on impersonation websites and search engine optimization (SEO) strategies to enhance the credibility of their malicious applications, thus evading detection.

At the core of this campaign is the exploitation of a zero-day vulnerability identified as CVE-2026-68820 in the Microsoft AFD.sys driver. This vulnerability enables attackers to escalate privileges and disable endpoint detection and response (EDR) visibility. Following responsible disclosure by Check Point Research, Microsoft issued a patch for this vulnerability as part of their August Patch Tuesday updates.

The Infection Chain

The attack begins with targeted spear-phishing lures that present attractive job opportunities at well-known companies in the defense, aerospace, and aviation sectors. While the precise methods of approach remain unclear, previous campaigns suggest that attackers likely utilize professional networking platforms such as LinkedIn or direct messaging applications to impersonate recruiters.

Two distinct infection chains have been identified in this campaign:

Infection Chain 1: DLL Sideloading

In this chain, victims are deceived into downloading an encrypted ZIP archive containing a legitimate PDF viewer executable, a malicious DLL, and an encrypted payload. When the executable is launched, the malicious DLL is loaded via DLL sideloading, extracting and executing an embedded payload in memory. This payload, referred to as MISTPEN, functions as a lightweight downloader that retrieves additional modules from Microsoft OneDrive, facilitating further exploitation.

Infection Chain 2: Trojanized PDF Viewer

The second infection chain involves fraudulent job offers impersonating Enveil, a privacy-enhancing technology company. Victims are instructed to download an encrypted ZIP archive containing SecurityPDF and a malicious PDF file. The trojanized PDF viewer is engineered to extract and execute an encrypted payload when a specially crafted PDF is opened, leading to the deployment of the Troy backdoor, a newly identified modular remote access trojan.

Technical Insights into the Malware

The Troy backdoor supports a wide array of commands, enabling extensive remote access and post-exploitation capabilities. It establishes connections with multiple command-and-control (C2) servers, allowing attackers to maintain control over compromised systems. The design of the backdoor facilitates various operations, including file exfiltration, process management, and in-memory code delivery.

Additionally, attackers have utilized compromised Roundcube webmail servers to host RelayShell, a PHP webshell that serves as a communication relay between the threat actor and infected endpoints. This method allows attackers to blend malicious communications with legitimate network traffic, complicating detection efforts.

Victimology and Implications

The Operation Dream Job campaign has predominantly targeted organizations involved in military technologies, including surveillance sensors, drones, and robotics. The global reach of this campaign has extended to South America and Western Europe, with notable activity observed in countries such as France, Germany, and India.

As the Lazarus Group continues to refine its operational techniques, the implications for organizations in the defense sector are significant. The combination of sophisticated malware, zero-day exploitation, and the use of compromised infrastructure underscores the necessity for heightened vigilance and robust cybersecurity measures.

For further details, you can access the full report by Check Point Research here.


Published on 2026-08-15 03:19:00 • By the Editorial Desk

For ongoing coverage and breaking updates, visit our Latest News section.

Share post:

Subscribe

Popular

More like this
Related

Saudi Arabia’s CASHIN partners with Syria to create national digital platform for petroleum derivatives

Saudi technology firm CASHIN has entered into a strategic partnership with Syria’s Ministry of Energy to develop a national digital platform for petroleum derivatives. This initiative marks a significant step in enhancing cooperation between Saudi Arabia and Syria in the…

Veeam highlights EMEA ‘shadow agent’ crisis as 70% of firms lack AI oversight

New research from Veeam, a company focused on data and AI trust, has unveiled a significant 'shadow agent' crisis affecting enterprises across the EMEA region. The study reveals that 70% of organizations acknowledge that automated AI workflows are engaging with…

Preorders open for iPhone 18 Pro and Pro Max ahead of September 18 release

Preorders are now open for the iPhone 18 Pro and Pro Max, which are set to be released on September 18, 2026. This announcement comes from The Verge, highlighting that early ordering is advisable for customers looking to secure their…

US lawmakers advocate for new AI regulations following Anthropic researchers’ extinction warning

A growing number of U.S. lawmakers are advocating for new regulations on artificial intelligence (AI) systems following alarming warnings from researchers at Anthropic. They caution that the rapid advancement of AI could potentially lead to human extinction. This call for…