started · updated
Lazarus Group targets defense sector with fake job offers and Windows zero-day
The Lazarus Group, a North Korean-linked threat actor, has launched a sophisticated cyberespionage campaign known as ‘Operation Dream Job.’ The operation specifically targets professionals in the defense, aerospace, and aviation sectors across Europe, India, and Brazil.
Attackers use social engineering by posing as recruiters on platforms like LinkedIn to offer fraudulent job opportunities. These offers entice victims to download malicious files, such as a modified PDF reader called ‘SecurityPDF’ or encrypted ZIP files. The campaign exploits a previously unknown Windows zero-day vulnerability, CVE-2026-68820, in the Microsoft AFD.sys driver to gain system-level privileges and bypass security software.
Once the system is compromised, the attackers deploy several malware components, including the MISTPEN downloader and the ‘Troy’ modular backdoor, which provides extensive remote control over the infected machine. The group also utilizes the FudModule rootkit to evade detection. Microsoft released a patch for the exploited Windows vulnerability on August 11, 2026.
Entities
Check Point Research · Lazarus Group · Lockheed Martin · Microsoft · North Korea
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] The campaign utilizes a modular backdoor named ‘Troy’ that features 17 different commands for system control. zap.aeiou.pt · www.it-daily.net
- [○ 1 SOURCE] Microsoft released a patch for the CVE-2026-68820 vulnerability on August 11, 2026. www.news9live.com
- [● 3 SOURCES] Attackers used fake job postings that impersonated companies such as Lockheed Martin and Enveil. 4gnews.pt · www.news9live.com · www.it-daily.net
- [● 7 SOURCES] The attackers exploited a Windows zero-day vulnerability, tracked as CVE-2026-68820, in the Microsoft AFD.sys driver. zap.aeiou.pt · www.news9live.com · borncity.com · www.infopoint-security.de · www.it-daily.net · +2 more
- [● 9 SOURCES] The Lazarus Group is conducting a cyberespionage campaign called ‘Operation Dream Job’ targeting the defense, aerospace, and aviation sectors. zap.aeiou.pt · 4gnews.pt · www.news9live.com · borncity.com · www.infopoint-security.de · +4 more
- [● 7 SOURCES] The campaign targets professionals in Europe, India, Brazil, and other regions. zap.aeiou.pt · 4gnews.pt · www.news9live.com · borncity.com · www.infopoint-security.de · +2 more
- [● 4 SOURCES] Victims are lured into downloading a modified PDF reader called ‘SecurityPDF’ to view fraudulent job descriptions. zap.aeiou.pt · 4gnews.pt · www.it-daily.net · research.checkpoint.com
- [● 3 SOURCES] The attackers use a malware component called MISTPEN to collect system information and execute tasks via Microsoft Graph and OneDrive. zap.aeiou.pt · 4gnews.pt · dev.to