Lazarus Group's 'Operation Dream Job' Targets Defense Sector with Zero-Day and New Backdoor
North Korean state-sponsored Lazarus group is actively targeting the defense sector with 'Operation Dream Job,' employing a zero-day vulnerability in Microsoft's AFD.sys driver and a new backdoor named Troy.

Check Point Research is tracking a sophisticated and persistent campaign, dubbed 'Operation Dream Job,' orchestrated by the Lazarus group, a threat actor widely attributed to North Korea. This ongoing operation has recently intensified its focus on the global defense sector, with a particular emphasis on organizations within the aerospace and aviation industries in Europe and India.
The latest iteration of the campaign sees Lazarus employing advanced techniques, including a zero-day vulnerability in Microsoft's AFD.sys driver (CVE-2026-68820). This vulnerability allows for local privilege escalation, enabling the attackers to gain SYSTEM privileges and disable endpoint detection and response (EDR) solutions. Following responsible disclosure by Check Point Research, Microsoft has addressed this critical flaw in its August 2026 Patch Tuesday updates.
In addition to the zero-day exploit, Lazarus is distributing a new backdoor, which Check Point Research has named 'Troy.' This backdoor is delivered through trojanized PDF viewers. These viewers are designed to execute malicious payloads embedded within specially crafted PDF documents. The threat actors are also leveraging impersonation websites and search engine optimization (SEO) techniques to distribute these malicious applications, aiming to enhance their credibility and evade detection.
The infection chain often begins with spear-phishing lures, presenting enticing job opportunities at well-known defense companies. Victims are directed to download malicious files, often disguised as legitimate software. One observed infection chain involves DLL sideloading, where a legitimate PDF viewer executable loads a malicious DLL. This DLL then decrypts and executes a payload in memory, which acts as a downloader for further malicious modules, including reconnaissance tools and persistence mechanisms.
Once persistence is established, the malware attempts to exploit CVE-2026-68820 to achieve privilege escalation. Successful exploitation allows the deployment of FudModule, a kernel-mode rootkit known to be used by Lazarus, granting the attackers deep control over the compromised system. The final payload is often the ForestTiger backdoor, providing long-term remote access for the threat actor.
Furthermore, Lazarus is exploiting vulnerabilities in Roundcube webmail servers, specifically CVE-2025-49113, to deploy 'RelayShell.' This PHP webshell repurposes compromised servers to act as relay nodes within the attacker's command-and-control infrastructure. In one documented instance, a compromised European organization was used to launch further spear-phishing attacks, leveraging the organization's reputation to target additional victims.
The 'Operation Dream Job' campaign highlights Lazarus's evolving tactics, techniques, and procedures (TTPs). The group's ability to discover and weaponize zero-day vulnerabilities, coupled with its use of sophisticated social engineering and diverse exploitation methods, poses a significant threat to critical infrastructure and defense organizations worldwide. The continuous development of new malware like Troy and the repurposing of compromised infrastructure underscore the persistent and adaptive nature of this threat actor.
Microsoft's August Patch Tuesday release includes a fix for CVE-2026-68820, the critical use-after-free flaw in WinSock's Ancillary Function Driver that North Korea's Lazarus Group exploited as a zero-day in early June. This exploitation was part of the 'Operation Dream Job' campaign, which targets defense sector organizations with social engineering and impersonation websites, distributing malware via trojanized applications and malicious PDFs. The new article also highlights that Microsoft addressed a total of 421 vulnerabilities in this month's release, with CVE-2026-68820 being one of two deemed 'notable' by Microsoft, alongside CVE-2026-62832, an elevation-of-privilege flaw.
This new reporting details the specific technical mechanisms employed by Lazarus in Operation Dream Job, including two distinct infection chains utilizing DLL sideloading and a trojanized PDF viewer. It also highlights the upgraded FudModule v3.1 rootkit's enhanced capabilities, such as tampering with Windows Smart App Control and a new generic security product blinding engine, alongside the use of MISTPEN for reconnaissance and privilege escalation via the CVE-2026-68820 exploit.
This new report details two distinct infection chains used in the Operation Dream Job campaign. One chain utilizes DLL sideloading to deploy the Mistpen malware downloader and exploit the afd.sys zero-day (CVE-2026-68820) for privilege escalation, leading to the ForestTiger backdoor. A second chain employs a trojanized PDF viewer to directly execute the Troy backdoor in memory, a new DLL implant with extensive command capabilities. The campaign also leverages compromised webmail and CMS platforms, infected with a previously undocumented PHP webshell called RelayShell, for command and control infrastructure.
This new reporting details a second, parallel infection chain used by Lazarus in Operation Dream Job. This chain involves a trojanized PDF viewer named SecurityPDF, which, when used to open a specially crafted PDF, extracts and executes an embedded payload. This payload installs a new backdoor dubbed 'Troy,' providing the attackers with remote access. Additionally, the campaign has been observed using compromised Roundcube webmail servers, vulnerable to CVE-2025-49113, to relay command-and-control traffic, deploying a previously undocumented PHP web shell called RelayShell.
CISA has issued a binding directive mandating that federal agencies patch CVE-2026-68820, a critical vulnerability in Windows' Winsock component, within two weeks. This directive highlights the severity of the bug, which North Korean state-sponsored actors have actively exploited as part of the long-running 'Operation Dream Job' campaign. The campaign specifically targets individuals applying for jobs in the defense and aerospace sectors, underscoring the persistent threat of nation-state espionage leveraging specific software flaws.
This new reporting details the sophisticated command-and-control (C2) infrastructure employed by the Lazarus Group in their 'Operation Dream Job' campaign. Specifically, the group is leveraging post-quantum cryptography (PQC) with the Kyber/ML-KEM standard for key exchange, making their communications significantly harder to intercept and analyze using traditional methods. Furthermore, the campaign utilizes compromised Roundcube webmail servers and PrestaShop sites for its C2 infrastructure, alongside a new PHP webshell dubbed RelayShell.
This new report from The Hacker News details the specific mechanism of the Lazarus Group's "Operation Dream Job" campaign, revealing that the attackers exploited a zero-day vulnerability in Microsoft's AFD.sys driver to achieve SYSTEM-level access. The vulnerability has since been patched by Microsoft, and the campaign targeted defense and aerospace organizations across multiple countries.