The North Korean threat actor known as Lazarus Group has exploited a newly patched zero-day vulnerability in Microsoft Windows to deploy a previously unseen backdoor targeting defense and aerospace companies in France, Germany, Brazil, and India. This activity is part of Operation Dream Job, a long-running cyber espionage campaign aimed at professionals worldwide.
According to reporting by The Hacker News, the attacks leverage the CVE-2026-68820 vulnerability, which has a CVSS score of 7.0. This privilege escalation flaw affects the Windows Ancillary Function Driver for WinSock (“AFD.sys”) and was patched by Microsoft in August 2026.
Victims are lured through fake recruiter messages and tricked into opening malicious PDFs or installing a trojanized PDF viewer. This leads to the installation of a backdoor named Troy, which grants remote access to compromised machines. The ultimate goal is to gain complete control over infected systems and bypass security measures.
Attack Methodology
Two distinct infection sequences have been identified:
- DLL side-loading: Victims download an encrypted archive that triggers a DLL side-loading chain. A malicious DLL displays a fake job description while stealthily downloading a lightweight downloader called MISTPEN, which communicates with threat actor-controlled infrastructure.
- Trojanized “SecurityPDF” viewer: Victims are instructed to download a PDF viewer from a site impersonating Enveil. This viewer monitors opened PDFs for specific markers and, if detected, launches a backdoor directly into memory.
The MISTPEN downloader loads various modules for reconnaissance and data exfiltration, including a local privilege escalation loader that enhances its capabilities. The attack chain employs an updated kernel-mode rootkit to evade detection by security software.
Infrastructure and Tactics
Notably, the campaign hijacks legitimate but compromised websites and vulnerable servers for command-and-control operations, making it difficult to distinguish malicious traffic from normal web activity. The attackers have also created at least three websites impersonating Enveil to distribute the trojanized PDF viewer.
Recent findings indicate that the Lazarus Group continues to refine its malware capabilities while maintaining the core elements of the Dream Job campaign, posing significant risks to critical sectors globally.
Sergey Shykevich, director of threat intelligence at Check Point Software, emphasized the dangers of this campaign, stating, “What makes this campaign so dangerous is not only the zero-day vulnerability – but also how Lazarus wove legitimate, trusted infrastructure into every stage of the attack.”
Follow Cyber Warriors Middle East for further global cybersecurity developments.


