Lazarus Operation Dream Job Uses AFD.sys Zero-Day and Troy Backdoor Against Defense

Share:

Check Point has detailed the latest wave of Operation Dream Job, a campaign by the North Korealinked Lazarus group that lures defense, aerospace, and aviation staff with fake job offers. Victims are tricked into opening booby-trapped PDF files or downloading a trojanised PDF viewer from lookalike websites, which quietly installs malware and, using a Windows zero-day (CVE-2026-68820, patched on 11 August), gains full SYSTEM control and blinds security tools. The attackers then run a new backdoor called Troy and hide their command-and-control traffic inside hacked legitimate websites, with confirmed victims in Europe, India, and Brazil.

1. Campaign Overview

Check Point Research attributes this wave of Operation Dream Job, active since early 2026, to the DPRK-linked Lazarus group. The actor poses as recruiters offering roles at well-known defense, aerospace, and aviation firms, then lures targets into opening malicious PDFs or downloading a trojanised PDF viewer. Two infection chains run in parallel, one using DLL sideloading and one using a modified viewer distributed from lookalike websites promoted through search engine optimisation. Confirmed victims span Western Europe (France and Germany), India, and Brazil, and one compromised French organisation was reused to spear-phish further targets. Check Point disclosed the zero-day on 28 July 2026, and Microsoft patched it on 11 August.

2. Attack Details

  1. Initial access
    Posing as recruiters on platforms such as LinkedIn, Lazarus delivers an encrypted archive or directs targets to lookalike vendor sites. One chain sideloads a malicious libmupdf.dll from a signed PDF viewer; the other uses a trojanised Security PDF viewer that decrypts and runs a payload hidden in a crafted PDF.
  2. Execution and staging
    Both chains launch MISTPEN, an in-memory downloader that uses the Microsoft Graph API and OneDrive for command and control. MISTPEN profiles the host, captures screenshots, and pulls further modules directly into memory without touching disk.
  3. Privilege escalation
    An in-memory loader retrieves FudModule v3.1, which exploits the AFD.sys zero-day CVE-2026-68820, a useafter-free race condition, to gain a kernel read/write primitive and escalate to SYSTEM on Windows 11 24H2 and 25H2. It then injects MISTPEN into a SYSTEM process to run with elevated privileges and no EDR visibility.
  4. Backdoor and command-and-control
    The intrusion ends with the ForestTiger backdoor or the new Troy backdoor for long-term access. Command and control is routed through compromised Roundcube, WordPress, and PrestaShop servers running the RelayShell webshell, accessed over commercial VPNs.

3. Payload Capabilities

The campaign strings together several Lazarus tools, each handling a stage of the intrusion:

  • FudModule v3.1 (kernel rootkit) Exploits CVE-2026-68820 in AFD.sys to reach SYSTEM, then blinds defenders by tearing down telemetry callbacks, killing 94 ETW providers, suppressing crash dumps, and disabling security products generically. A new stage tampers with Windows Smart App Control by resetting the code-integrity policy.
  • MISTPEN downloader A fileless downloader that communicates through attacker-controlled OneDrive files over the Microsoft Graph API, reflectively loads DLL modules in memory, and runs reconnaissance, process-listing, and screenshot modules that report back for exfiltration.
  • Troy backdoor A new 64-bit modular implant with 17 commands covering reconnaissance, file transfer, command execution, process control, and in-memory DLL injection, beaconing over HTTP to three configured C2 servers.
  • RelayShell C2 relay A PHP webshell planted on compromised Roundcube, WordPress, and PrestaShop servers that turns each host into a relay node, letting Lazarus hide command and control inside legitimate, trusted web infrastructure.

4. Adversary Toolkit

Tool / IndicatorTypeFunction
MISTPENIn-memory
downloader
Fileless downloader using Microsoft Graph and OneDrive to fetch and reflectively load further modules.
FudModule v3.1JaKernel-mode rootkitExploits CVE-2026-68820 for SYSTEM and disables EDR, ETW, and Smart App Control.
ForestTigerBackdoor (Lazarus) Well-documented Lazarus backdoor providing long-term remote access to compromised hosts.
Troy Modular backdoorNew 64-bit RAT with 17 commands and three C2 servers for post compromise operations.
RelayShellPHP relay webshellRepurposes compromised web servers as command-and control relay nodes.

5.Indicators of Compromise (IOCs)

Full IOC collection published to VirusTotal:

  • https://www.virustotal.com/gui/collection/bb9490c1520f1003c9688ac76e33336ff47ccc0264e99cf432d5651c1548e6f/iocs

6. Recommendations

  1. Apply the August Patch Tuesday fix for CVE-2026-68820 in the AFD.sys driver, prioritising Windows 11 24H2 and 25H2 (builds 26100 and 26200), to remove the SYSTEM privilege-escalation zero-day.
  2. Warn staff, especially in defense and aerospace, about recruiter and job-offer lures that deliver boobytrapped PDFs and trojanised PDF viewers from lookalike, search-promoted websites, and install software only from verified vendor sources.
  3. Hunt for a signed PDF viewer sideloading libmupdf.dll, SecurityPDF or new.exe running from %TEMP%, PDF files containing the marker “This document is encrypted with sumatrapdf reader”, and processes that disable ETW providers, reset Smart App Control, or spawn a SYSTEM msiexec.exe through services.exe.
  4. Update Roundcube webmail to fix CVE-2025-49113 and rotate any exposed webmail credentials, since Lazarus authenticates with leaked credentials and turns compromised Roundcube, WordPress, and PrestaShop servers into command-and-control relays.
  5. Block the IOCs at their respective controls, https://www.virustotal.com/gui/collection/bb9490c1520f1003c9688ac76e33336ff47ccc0264e99cf43f2d5651c1548e6f/iocs

7. Sources

  • https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
  • https://blog.checkpoint.com/research/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert