< Back to all clusters
[TECHNOLOGY] · Brazil, Germany, France, India, United States · 10 sources

started · updated

Lazarus Group targets defense sector with fake job offers and Windows zero-day

The Lazarus Group, a North Korean-linked threat actor, has launched a sophisticated cyberespionage campaign known as ‘Operation Dream Job.’ The operation specifically targets professionals in the defense, aerospace, and aviation sectors across Europe, India, and Brazil.

Attackers use social engineering by posing as recruiters on platforms like LinkedIn to offer fraudulent job opportunities. These offers entice victims to download malicious files, such as a modified PDF reader called ‘SecurityPDF’ or encrypted ZIP files. The campaign exploits a previously unknown Windows zero-day vulnerability, CVE-2026-68820, in the Microsoft AFD.sys driver to gain system-level privileges and bypass security software.

Once the system is compromised, the attackers deploy several malware components, including the MISTPEN downloader and the ‘Troy’ modular backdoor, which provides extensive remote control over the infected machine. The group also utilizes the FudModule rootkit to evade detection. Microsoft released a patch for the exploited Windows vulnerability on August 11, 2026.

Entities

Check Point Research · Lazarus Group · Lockheed Martin · Microsoft · North Korea

Claims

What the coverage asserts, and how many sources carry each claim.