New Threat Unveiled
In recent investigations by Check Point Research (CPR), a unit of Check Point Software Technologies, a new cyber campaign known as
Operation Dream Job has been identified. This operation is orchestrated by the North Korean state-sponsored threat group
Lazarus and focuses on deceiving professionals in the defense and aerospace sectors. The group employs fake job advertisements to lure targets into malicious actions, particularly in Europe and India.
Key Findings
CPR has confirmed that Lazarus is exploiting a previously unknown vulnerability in Windows denoted as
CVE-2026-68820. This allows the attackers to take complete control of infected systems while evading detection through Endpoint Detection and Response (EDR) systems. The vulnerability was responsibly disclosed by Check Point and scheduled for a fix in the upcoming Patch Tuesday on
August 11, 2026.
Victims are approached by purported recruitment agents who entice them into opening harmful PDF documents or installing a Trojanized PDF viewer. This viewer secretly installs a newly identified backdoor, granting attackers remote access to compromised computers.
Instead of managing their own servers, the attackers hijack legitimate compromised websites and webmail servers to facilitate command relay, which obscures malicious traffic against regular activities.
The Mechanics of Operation Dream Job
Since early 2026, CPR has tracked this campaign targeting professionals in the defense and aerospace sectors, where interest in attractive job offers is leveraged. Lazarus attackers masquerade as recruiters on platforms like LinkedIn or messaging apps, presenting positions from renowned firms to lure victims into downloading malicious content. This method, while simple, effectively targets career ambitions and employs sophisticated social engineering.
Trust as a Weapon
This campaign begins with spear phishing disguised as enticing job offers from defense giants like
Lockheed Martin and privacy technology firm
Enveil. At least three fraudulent
Enveil websites, optimized for SEO, emerged in the process, allowing attackers to appear legitimate in search engine results, directing victims to download malware instead.
Documents masquerading as job postings from Lockheed Martin were delivered through PDFs, demonstrating that traditional indicators to identify phishing attempts are becoming ineffective. Users must remain vigilant, recognizing that even search results and download sources may be compromised.
New Tools and Evolving Techniques
The use of a Trojan, dubbed
Troy, is noted, concealed as a PDF viewer called
SecurityPDF. This marks the first public acknowledgment of a modular backdoor supporting 17 operator commands. Furthermore, the new version of
FudModule (v3.1) exploits zero-day vulnerabilities affecting
AFD.sys to obtain SYSTEM privileges and disable EDR security tools. This progression of tactics illustrates an adaptability in the attackers' toolkit to bypass detection used by defense organizations.
International Implications
Lazarus's campaign has had global ramifications, targeting the defense sector across France, Germany, Brazil, and India. The latter is of particular concern due to its booming defense and aerospace industry, making it a primary target.
Exploiting Genuine Infrastructure
Rather than using dedicated servers, Lazarus now utilizes compromised legitimate webmail services like
Roundcube or content management systems (CMS) to conduct its operations. By leveraging vulnerabilities that have already been patched, alongside credentials obtained from dark web leaks, these entities repurpose at least 17 compromised servers for command and control.
An Escalating Threat
An illustration of this tactic occurred in France, where a compromised organization was commandeered to amplify spear phishing attacks globally. By leveraging the credibility of a real entity, the attackers enhanced the trustworthiness of their operations, revealing that corporate breaches have now broader implications.
Sergey Shykevich, the director of threat intelligence at Check Point, remarked, “This campaign is perilous not merely because of the zero-day vulnerabilities but also due to Lazarus integrating already trusted infrastructure at all phases of the attack. With the convergence of legitimate vendors, compromised organizations, and search result manipulation, traditional advice on spotting phishing links is becoming obsolete.”
Conclusion
In today’s cyber landscape, where authenticity can be forged, it’s critical to maintain a
zero trust mindset. Users are encouraged to apply due diligence in verifying software updates through official channels and to approach familiar websites with caution, as trust can no longer be assumed. Maintaining secure practices could mitigate potential threats in an increasingly complex cyber environment.