Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
2026-08-11 • Checkpoint •
Lazarus expanded Operation Dream Job against defense, aerospace, and aviation organizations by combining fraudulent recruitment lures with trojanized PDF viewers and impersonation websites. The campaign exploited the Windows AFD.sys zero-day CVE-2026-68820 to run an updated FudModule rootkit with SYSTEM privileges and deployed MISTPEN, ForestTiger, and the newly documented Troy backdoor. Compromised Roundcube and CMS servers infected with the new RelayShell webshell served as command-and-control relay nodes. Microsoft patched CVE-2026-68820 on August 11, 2026, following Check Point's responsible disclosure.
Indicators of Compromise
Related Actors
Related Reports
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus
2026-07-06 •
35% Match
#Cryptocurrency
#Harmony
#AxieInfinity
#OrbitBridge
#MoneyLaundering
#Lazarus
#KelpDAO
Shares tag: Lazarus
Shares tag: Lazarus
Shares tag: Lazarus
Shares tag: Lazarus