Lazarus Group’s Operation Dream Job Exploits Zero-Day Vulnerability to Target Defense Sector in 2026 Cyberattacks
In early 2026, a significant wave of cyberattacks emerged under the name Operation Dream Job, attributed to the infamous Lazarus Group, which is associated with North Korea. This campaign has primarily focused on organizations within the defense sector, particularly in Europe and India, employing advanced techniques to exploit vulnerabilities and gain unauthorized access to sensitive data.
The latest phase of this operation involves the distribution of a modified PDF viewer known as SecurityPDF. This tool is designed to execute malicious payloads embedded in specially crafted PDF documents. This development marks a notable shift in the group’s tactics, as they increasingly rely on impersonation websites and search engine optimization (SEO) strategies to enhance the credibility of their malicious applications, thus evading detection.
At the core of this campaign is the exploitation of a zero-day vulnerability identified as CVE-2026-68820 in the Microsoft AFD.sys driver. This vulnerability enables attackers to escalate privileges and disable endpoint detection and response (EDR) visibility. Following responsible disclosure by Check Point Research, Microsoft issued a patch for this vulnerability as part of their August Patch Tuesday updates.
The Infection Chain
The attack begins with targeted spear-phishing lures that present attractive job opportunities at well-known companies in the defense, aerospace, and aviation sectors. While the precise methods of approach remain unclear, previous campaigns suggest that attackers likely utilize professional networking platforms such as LinkedIn or direct messaging applications to impersonate recruiters.
Two distinct infection chains have been identified in this campaign:
Infection Chain 1: DLL Sideloading
In this chain, victims are deceived into downloading an encrypted ZIP archive containing a legitimate PDF viewer executable, a malicious DLL, and an encrypted payload. When the executable is launched, the malicious DLL is loaded via DLL sideloading, extracting and executing an embedded payload in memory. This payload, referred to as MISTPEN, functions as a lightweight downloader that retrieves additional modules from Microsoft OneDrive, facilitating further exploitation.
Infection Chain 2: Trojanized PDF Viewer
The second infection chain involves fraudulent job offers impersonating Enveil, a privacy-enhancing technology company. Victims are instructed to download an encrypted ZIP archive containing SecurityPDF and a malicious PDF file. The trojanized PDF viewer is engineered to extract and execute an encrypted payload when a specially crafted PDF is opened, leading to the deployment of the Troy backdoor, a newly identified modular remote access trojan.
Technical Insights into the Malware
The Troy backdoor supports a wide array of commands, enabling extensive remote access and post-exploitation capabilities. It establishes connections with multiple command-and-control (C2) servers, allowing attackers to maintain control over compromised systems. The design of the backdoor facilitates various operations, including file exfiltration, process management, and in-memory code delivery.
Additionally, attackers have utilized compromised Roundcube webmail servers to host RelayShell, a PHP webshell that serves as a communication relay between the threat actor and infected endpoints. This method allows attackers to blend malicious communications with legitimate network traffic, complicating detection efforts.
Victimology and Implications
The Operation Dream Job campaign has predominantly targeted organizations involved in military technologies, including surveillance sensors, drones, and robotics. The global reach of this campaign has extended to South America and Western Europe, with notable activity observed in countries such as France, Germany, and India.
As the Lazarus Group continues to refine its operational techniques, the implications for organizations in the defense sector are significant. The combination of sophisticated malware, zero-day exploitation, and the use of compromised infrastructure underscores the necessity for heightened vigilance and robust cybersecurity measures.
For further details, you can access the full report by Check Point Research here.
Published on 2026-08-15 03:19:00 • By the Editorial Desk
For ongoing coverage and breaking updates, visit our Latest News section.

