← Back to feed
Vulnerabilities & PatchesEmerging2 sourcesAug 11, 2026 · 17:30via Check Point Research

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

Brief

Key Points

  • Check Point Research is tracking a long‑running campaign called Operation Dream Job , targeting organizations worldwide, with a particular focus on the defense sector. The campaign is affiliated to DPRK-linked  Lazarus group  and its latest wave focuses on the defense sector in Europe and India.
  • In the latest variant of the Operation Dream Job campaign, the threat actor distributed  SecurityPDF , a modified PDF viewer designed to open attacker-crafted PDF documents and execute a new backdoor which we named  Troy .
  • During the intrusion, the threat actor exploited  CVE-2026-68820 , a zero-day vulnerability in the Microsoft  AFD.sys  driver, to deploy a new version of  FudModule , Lazarus’ kernel-mode rootkit. Following Check Point Research responsible disclosure, Microsoft released a patch as part of their August Patch Tuesday updates.
Read more on Check Point Research

All credited sources

Highest-trust first. Dates are the publisher's original publish time.

Check Point ResearchPrimary··trust 1.38

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

Key Points

  • Check Point Research is tracking a long‑running campaign called Operation Dream Job , targeting organizations worldwide, with a particular focus on the defense sector. The campaign is affiliated to DPRK-linked  Lazarus group  and its latest wave focuses on the defense sector in Europe and India.
  • In the latest variant of the Operation Dream Job campaign, the threat actor distributed  SecurityPDF , a modified PDF viewer designed to open attacker-crafted PDF documents and execute a new backdoor which we named  Troy .
  • During the intrusion, the threat actor exploited  CVE-2026-68820 , a zero-day vulnerability in the Microsoft  AFD.sys  driver, to deploy a new version of  FudModule , Lazarus’ kernel-mode rootkit. Following Check Point Research responsible disclosure, Microsoft released a patch as part of their August Patch Tuesday updates.
  • Lazarus also used  CVE-2025-49113  to exploit vulnerable  Roundcube  webmail servers. The compromised servers were infected with  RelayShell , a PHP webshell that repurposes compromised web servers as relay nodes within the attacker’s command-and-control infrastructure.
  • At least in one case, a compromised organization in Western Europe was leveraged to conduct a spear-phishing campaign, allowing the attackers to abuse the organization’s reputation and trust to target additional victims.

Introduction

Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries.

We observed the threat actor distributing modified PDF viewers designed to execute malicious payloads embedded within specially crafted PDF files, opened by the user.

Read more →
Malware.news··trust 0.88

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

Key Points

  • Check Point Research is tracking a long‑running campaign called Operation Dream Job , targeting organizations worldwide, with a particular focus on the defense sector. The campaign is affiliated to DPRK-linked  Lazarus group  and its latest wave focuses on the defense sector in Europe and India.
  • In the latest variant of the Operation Dream Job campaign, the threat actor distributed  SecurityPDF , a modified PDF viewer designed to open attacker-crafted PDF documents and execute a new backdoor which we named  Troy .
  • During the intrusion, the threat actor exploited  CVE-2026-68820 , a zero-day vulnerability in the Microsoft  AFD.sys  driver, to deploy a new version of  FudModule , Lazarus’ kernel-mode rootkit. Following Check Point Research responsible disclosure, Microsoft released a patch as part of their August Patch Tuesday updates.
  • Lazarus also used  CVE-2025-49113  to exploit vulnerable  Roundcube  webmail servers. The compromised servers were infected with  RelayShell , a PHP webshell that repurposes compromised web servers as relay nodes within the attacker’s command-and-control infrastructure.
  • At least in one case, a compromised organization in Western Europe was leveraged to conduct a spear-phishing campaign, allowing the attackers to abuse the organization’s reputation and trust to target additional victims.

Introduction

Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries.

Read more →