A new wave of the DPRK-linked Lazarus group’s long-running Operation Dream Job is revealing that the campaign now exploits a previously unknown Windows kernel vulnerability to seize full system control while evading endpoint detection entirely.
According to Check Point, the campaign, active since early 2026, primarily targets the global defense sector, with a sharp focus on aerospace, aviation, and military technology firms in Europe and India.
Posing as recruiters likely via LinkedIn or direct messaging, the attackers lure victims with fake job offers from well-known companies, ultimately directing them to download malicious files.
Hackers Weaponize Job Offers With Zero-Day Exploit
Check Point identified two parallel infection chains. The first uses DLL sideloading: a signed PDF viewer loads a malicious DLL that decrypts and runs MISTPEN, a lightweight in-memory downloader that abuses the Microsoft Graph API to fetch modules from OneDrive.
The second, newer chain distributes SecurityPDF, a trojanized MuPDF-based PDF viewer impersonating the privacy-tech firm Enveil.
When a victim opens a specially crafted PDF, the app checks for a hidden marker, decrypts an embedded payload with a single-byte XOR key, and ultimately launches it, deploying a previously undocumented backdoor named Troy.

The most alarming discovery is a zero-day local privilege escalation flaw in Microsoft’s AFD.sys driver, which manages Windows socket handling.
The vulnerability is a use-after-free race condition that occurs when concurrent threads access socket state without proper synchronization, granting attackers access to a kernel read/write primitive.
This is exploited to deploy a new variant of FudModule v3.1, Lazarus’ signature kernel-mode rootkit, achieving SYSTEM privileges while disabling EDR telemetry including ETW providers, minifilter drivers, and crash-dump logging.
Check Point reported the bug to Microsoft on July 28, 2026; it was confirmed within days, assigned CVE-2026-68820 on August 5, and patched on Patch Tuesday, August 11.
Compared to the 2024 FudModule v3, this version drops Defender- and AhnLab-specific bypasses in favor of generic security-product suppression, and adds new functionality to tamper with Windows Smart App Control by resetting its reputable-policy state and forcing a code-integrity policy reload.
Troy, a modular 64-bit DLL implant, supports 17 operator commands covering reconnaissance, file exfiltration, remote shell access, in-memory DLL injection, and configuration updates communicating over HTTP with Base64-encoded JSON task envelopes.
For command-and-control, Lazarus shifted from WordPress and SharePoint toward compromised Roundcube webmail servers, exploiting CVE-2025-49113, a critical PHP object-deserialization RCE using leaked dark-web credentials.
Compromised servers, along with hijacked PrestaShop sites, host RelayShell, a newly identified PHP web shell that turns infected servers into relay nodes rather than direct command executors, using a file-based messaging channel between victim and operator sessions.
Check Point identified at least 17 unique relay identifiers, with operators connecting via commercial VPN services such as ExpressVPN to mask their origin.
Victims spanned France, Germany, Brazil, and India, with one compromised French organization later weaponized to launch further spear-phishing attacks, borrowing its trusted reputation to target new victims.
The campaign underscores Lazarus’ continued shift toward stealthier, infrastructure-abusing tradecraft that blends zero-day exploitation, SEO-driven malware distribution, and legitimate web servers to mask malicious traffic as normal network activity.
| IOC Category | IOC Type | Value |
|---|---|---|
| DLL Loader/Dropper | SHA-256 | 2b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca8 |
| DLL Loader/Dropper | SHA-256 | 3a02d0d798e8d35555776886d92b20ff38a101c9ef7e0eebc8ce5d259516525a |
| DLL Loader/Dropper | SHA-256 | 92106b0c62a0a42678232f8273f030b2d3c8e92efce81b98b9eec70cfe98afa1 |
| DLL Loader/Dropper | SHA-256 | 396192d92d17ace1a521f1351eeeba2825e60badd0d799cc5c338e4934b3c82c |
| DLL Loader/Dropper | SHA-256 | f7e620134ca935067797ab957317b346ce0df84a4e9b9ca54a6acc9b75afda4d |
| DLL Loader/Dropper | SHA-256 | 75b93a7103b0562f6497d30052c0c5cf7aa58c1bf0e9297022b74469a7f096f1 |
| DLL Loader/Dropper | SHA-256 | a45144d22cac70a45d71cf4dffa4efbc373658779a56cf1300d6ac863d6cc7e2 |
| DLL Loader/Dropper | SHA-256 | 1de949c71efcfb0ffc41f33d38833dbc4b082075b1a540fc68c18c535d7ad86c |
| DLL Loader/Dropper | SHA-256 | 4c9b804d6155b29f1e27a9ffe531e10bc42a7bdab42f905b50146bf2026768d9 |
| DLL Loader/Dropper | SHA-256 | 29e24c007549e51319ff3aee011da6f9f93568e8c85a5ad69c9e53bd3f4533a2 |
| DLL Loader/Dropper | SHA-256 | 4ebdce2f47c23ff8c9e8e80c8b5239c7a5764da31cd3ab8f0505926890adc105 |
| DLL Loader/Dropper | SHA-256 | c2aa28bb5e2a749c693712008276f311edd912f689371ef9e8a1ee5fb4167461 |
| MISTPEN | SHA-256 | 2db25ac41a66aa523c79e23e00443573530dd7bd82b8371bcc87bd7232e141eb |
| MISTPEN | SHA-256 | 5278ee922838352f1480a73e971161017d643a80b7ec22bf725897dfd088696d |
| MISTPEN | SHA-256 | b4082d21070d9ddf53fde4ea22524d09e41ec9826ce63cef3c6235e458d21afb |
| MISTPEN | SHA-256 | fb3fc5626f68677fb1269a2fefbe70e719211b4065e836ab92e06a8210139a2d |
| MISTPEN | SHA-256 | ea7056f2bf36c66a61ff787ff5be975a85f534c3c5ca178791dac2504db2c619 |
| MISTPEN | SHA-256 | 13d10bc99f7f7abe7ee0902be87920b73b2ea41bd9683dbfcad340dacbcdef79 |
| MISTPEN | SHA-256 | 4fd32432341dfcf54d0517a6bbc38e5d265be70933493e4183c2a340cdde9a2d |
| MISTPEN | SHA-256 | 4dd792c9f672bbdcc8d363d745994efe90f4ffc5fdc2c059c8e379a48ad6a68a |
| MISTPEN | SHA-256 | ba96c603e44046de703c67b2c3b7e4ca974afef7b437a0244418bc4edc781bb7 |
| ForestTiger | SHA-256 | 72dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289 |
| ForestTiger | SHA-256 | 231b1ef8b95bf77887d5377e2a60f649035e78f543af1b82877db36a5759d858 |
| ForestTiger | SHA-256 | 6da9b1e6f3315ceb77dd14a937a26cc3602bf6a7e2c2ecafb3c65ce5319837be |
| ForestTiger | SHA-256 | a0578a2b7821d7e2c573530648f26d7a0d98b373ab24fb7f0c792736761e542d |
| ForestTiger | SHA-256 | 82268052f94df6f4870d02e57b18d4c54136cc7a8c8d80ad162631f99462c943 |
| FudModule | SHA-256 | 3b6378df8442e63a6ed7317075913e4720847a510d95022d4a8347b2637c245d |
| PDF Payload | SHA-256 | a673ae661593c0de9bbb815593b816a6853dad6d55ad5042d2ef1875cd13d6e7 |
| PDF Payload | SHA-256 | 8ce6c29f92dc45b1474417cbdff4ed0c18e58fa63e3a071ee9f85aa9d2aac07c |
| PDF Payload | SHA-256 | acb97cec84e08b89f41967a24e965d1fd2c51751cef158f7aa35bb4306b87b97 |
| PDF Payload | SHA-256 | 3601060c62edeeaa49def6a13be6e126e1024ce011faad4e2d9f585ccf6bd5a6 |
| PDF Payload | SHA-256 | fecf12088843801215898442bd1ff3e266f29d14e29a94780e857f69c4915d6b |
| PDF Payload | SHA-256 | d578c28c9afe7457a0d81f6701332ef8197e8f7468de654935fb29a50ea66459 |
| SecurityPDF.exe | SHA-256 | 743172aab606974b054a64561534ae66baa3a840657f79d7c6fa18350e8d45d1 |
| SecurityPDF.exe | SHA-256 | db3d69b7eeda2e35e23006bf4b7e206281fce809584207214fc213f9bc30376d |
| Troy Backdoor | SHA-256 | 590fb6ae19480d694e08ee85859cad8066f2f87e7e5abba2960c6d115e1615d6 |
| Troy Backdoor | SHA-256 | 68d4fba7b1300a59cd6212c08910a260cd71b40cd9f51cac933030a68faac0bb |
| Troy Backdoor | SHA-256 | a738059ce07c951c31ab2da3d93d8f69bff32f9b7d933dbf5943441b9cc99075 |
| RelayShell | SHA-256 | 21c3ad4838c4324bc5f081021da5fb2e9073d0c9304087811c21eb47c9e22762 |
| RelayShell | SHA-256 | cc4e06aa378a190f71384c03023bb3d18a6d66e297d46701220e132963d2e222 |
| SecurityPDF Website / Troy C2 | Domain | envell[.]xyz |
| SecurityPDF Website / Troy C2 | Domain | enveil[.]online |
| SecurityPDF Website / Troy C2 | Domain | uxtramine[.]org |
| SecurityPDF Website / Troy C2 | IPv4 address | 135.181.67[.]203 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN. Gain complete phishing visibility to strengthen your SOC and reduce MTTR