Lazarus Group’s Operation Dream Job Exploits Zero-Day Vulnerability in New Campaign
In early 2026, Check Point Research began tracking a significant wave of cyberattacks under the banner of Operation Dream Job, attributed to the notorious Lazarus Group, which is linked to North Korea. This campaign has primarily targeted organizations in the defense sector, particularly in Europe and India, leveraging sophisticated techniques to exploit vulnerabilities and gain unauthorized access to sensitive information.
The latest iteration of this campaign has seen the distribution of a modified PDF viewer, dubbed SecurityPDF, which is designed to execute malicious payloads embedded within specially crafted PDF documents. This marks a notable evolution in the group’s tactics, as they have increasingly relied on impersonation websites and search engine optimization (SEO) techniques to enhance the credibility of their malicious applications, thereby evading detection.
Central to this campaign is the exploitation of a zero-day vulnerability, identified as CVE-2026-68820, in the Microsoft AFD.sys driver. This vulnerability allows attackers to escalate privileges and disable endpoint detection and response (EDR) visibility. Following responsible disclosure by Check Point, Microsoft released a patch for this vulnerability as part of their August Patch Tuesday updates.
The Infection Chain
The attack begins with targeted spear-phishing lures that present enticing job opportunities at well-known companies within the defense, aerospace, and aviation sectors. While the exact methods of approach remain unclear, previous campaigns suggest that the attackers likely utilize professional networking platforms like LinkedIn or direct messaging applications to pose as recruiters.
Two distinct infection chains have been identified in this campaign:
Infection Chain 1: DLL Sideloading
In this chain, victims are tricked into downloading an encrypted ZIP archive containing a legitimate PDF viewer executable, a malicious DLL, and an encrypted payload. When the executable is launched, the malicious DLL is loaded via DLL sideloading, which extracts and executes an embedded payload in memory. This payload, known as MISTPEN, acts as a lightweight downloader that retrieves additional modules from Microsoft OneDrive, facilitating further exploitation.
Infection Chain 2: Trojanized PDF Viewer
The second infection chain involves fraudulent job offers impersonating Enveil, a privacy-enhancing technology company. Victims are instructed to download an encrypted ZIP archive containing SecurityPDF and a malicious PDF file. The trojanized PDF viewer is designed to extract and execute an encrypted payload when a specially crafted PDF is opened, leading to the deployment of the Troy backdoor, a newly identified modular remote access trojan.
Technical Insights into the Malware
The Troy backdoor supports a wide range of commands, enabling extensive remote access and post-exploitation capabilities. It establishes connections with multiple command-and-control (C2) servers, allowing attackers to maintain control over compromised systems. The backdoor’s design facilitates various operations, including file exfiltration, process management, and in-memory code delivery.
Additionally, the attackers have utilized compromised Roundcube webmail servers to host RelayShell, a PHP webshell that acts as a communication relay between the threat actor and infected endpoints. This approach allows the attackers to blend malicious communications with legitimate network traffic, making detection more challenging.
Victimology and Implications
The Operation Dream Job campaign has predominantly targeted organizations involved in military technologies, including surveillance sensors, drones, and robotics. The global reach of this campaign has extended to South America and Western Europe, with notable activity observed in countries like France, Germany, and India.
As the Lazarus Group continues to refine its operational techniques, the implications for organizations in the defense sector are significant. The combination of sophisticated malware, zero-day exploitation, and the use of compromised infrastructure underscores the need for heightened vigilance and robust cybersecurity measures.
In conclusion, the latest findings from Check Point Research illustrate the evolving tactics of the Lazarus Group, emphasizing the importance of proactive defense strategies to mitigate the risks posed by such advanced persistent threats. For further details, you can access the full report by Check Point Research here.
Readers can also explore current and upcoming editions through the Cyber Warriors Middle East magazine section.


