VYPR
researchPublished Aug 11, 2026· 1 source

Lazarus Group's 'Operation Dream Job' Targets Defense Sector with Zero-Day and New Backdoor

North Korean state-sponsored Lazarus group is actively targeting the defense sector with 'Operation Dream Job,' employing a zero-day vulnerability in Microsoft's AFD.sys driver and a new backdoor named Troy.

Check Point Research is tracking a sophisticated and persistent campaign, dubbed 'Operation Dream Job,' orchestrated by the Lazarus group, a threat actor widely attributed to North Korea. This ongoing operation has recently intensified its focus on the global defense sector, with a particular emphasis on organizations within the aerospace and aviation industries in Europe and India.

The latest iteration of the campaign sees Lazarus employing advanced techniques, including a zero-day vulnerability in Microsoft's AFD.sys driver (CVE-2026-68820). This vulnerability allows for local privilege escalation, enabling the attackers to gain SYSTEM privileges and disable endpoint detection and response (EDR) solutions. Following responsible disclosure by Check Point Research, Microsoft has addressed this critical flaw in its August 2026 Patch Tuesday updates.

In addition to the zero-day exploit, Lazarus is distributing a new backdoor, which Check Point Research has named 'Troy.' This backdoor is delivered through trojanized PDF viewers. These viewers are designed to execute malicious payloads embedded within specially crafted PDF documents. The threat actors are also leveraging impersonation websites and search engine optimization (SEO) techniques to distribute these malicious applications, aiming to enhance their credibility and evade detection.

The infection chain often begins with spear-phishing lures, presenting enticing job opportunities at well-known defense companies. Victims are directed to download malicious files, often disguised as legitimate software. One observed infection chain involves DLL sideloading, where a legitimate PDF viewer executable loads a malicious DLL. This DLL then decrypts and executes a payload in memory, which acts as a downloader for further malicious modules, including reconnaissance tools and persistence mechanisms.

Once persistence is established, the malware attempts to exploit CVE-2026-68820 to achieve privilege escalation. Successful exploitation allows the deployment of FudModule, a kernel-mode rootkit known to be used by Lazarus, granting the attackers deep control over the compromised system. The final payload is often the ForestTiger backdoor, providing long-term remote access for the threat actor.

Furthermore, Lazarus is exploiting vulnerabilities in Roundcube webmail servers, specifically CVE-2025-49113, to deploy 'RelayShell.' This PHP webshell repurposes compromised servers to act as relay nodes within the attacker's command-and-control infrastructure. In one documented instance, a compromised European organization was used to launch further spear-phishing attacks, leveraging the organization's reputation to target additional victims.

The 'Operation Dream Job' campaign highlights Lazarus's evolving tactics, techniques, and procedures (TTPs). The group's ability to discover and weaponize zero-day vulnerabilities, coupled with its use of sophisticated social engineering and diverse exploitation methods, poses a significant threat to critical infrastructure and defense organizations worldwide. The continuous development of new malware like Troy and the repurposing of compromised infrastructure underscore the persistent and adaptive nature of this threat actor.

Synthesized by Vypr AI