Hackers Weaponize Job Offers With Zero-Day Exploit to Gain Silent System Access

A new wave of the DPRK-linked Lazarus group’s long-running Operation Dream Job is revealing that the campaign now exploits a previously unknown Windows kernel vulnerability to seize full system control while evading endpoint detection entirely.

According to Check Point, the campaign, active since early 2026, primarily targets the global defense sector, with a sharp focus on aerospace, aviation, and military technology firms in Europe and India.

Posing as recruiters likely via LinkedIn or direct messaging, the attackers lure victims with fake job offers from well-known companies, ultimately directing them to download malicious files.

Hackers Weaponize Job Offers With Zero-Day Exploit

Check Point identified two parallel infection chains. The first uses DLL sideloading: a signed PDF viewer loads a malicious DLL that decrypts and runs MISTPEN, a lightweight in-memory downloader that abuses the Microsoft Graph API to fetch modules from OneDrive.

The second, newer chain distributes SecurityPDF, a trojanized MuPDF-based PDF viewer impersonating the privacy-tech firm Enveil.

When a victim opens a specially crafted PDF, the app checks for a hidden marker, decrypts an embedded payload with a single-byte XOR key, and ultimately launches it, deploying a previously undocumented backdoor named Troy.

Windows AFD.sys Zero-Day Attack Chain (Source : CheckPoint)
Windows AFD.sys Zero-Day Attack Chain (Source : CheckPoint)

The most alarming discovery is a zero-day local privilege escalation flaw in Microsoft’s AFD.sys driver, which manages Windows socket handling.

The vulnerability is a use-after-free race condition that occurs when concurrent threads access socket state without proper synchronization, granting attackers access to a kernel read/write primitive.

This is exploited to deploy a new variant of FudModule v3.1, Lazarus’ signature kernel-mode rootkit, achieving SYSTEM privileges while disabling EDR telemetry including ETW providers, minifilter drivers, and crash-dump logging.

Check Point reported the bug to Microsoft on July 28, 2026; it was confirmed within days, assigned CVE-2026-68820 on August 5, and patched on Patch Tuesday, August 11.

Compared to the 2024 FudModule v3, this version drops Defender- and AhnLab-specific bypasses in favor of generic security-product suppression, and adds new functionality to tamper with Windows Smart App Control by resetting its reputable-policy state and forcing a code-integrity policy reload.

Troy, a modular 64-bit DLL implant, supports 17 operator commands covering reconnaissance, file exfiltration, remote shell access, in-memory DLL injection, and configuration updates communicating over HTTP with Base64-encoded JSON task envelopes.

For command-and-control, Lazarus shifted from WordPress and SharePoint toward compromised Roundcube webmail servers, exploiting CVE-2025-49113, a critical PHP object-deserialization RCE using leaked dark-web credentials.

Compromised servers, along with hijacked PrestaShop sites, host RelayShell, a newly identified PHP web shell that turns infected servers into relay nodes rather than direct command executors, using a file-based messaging channel between victim and operator sessions.

Check Point identified at least 17 unique relay identifiers, with operators connecting via commercial VPN services such as ExpressVPN to mask their origin.

Victims spanned France, Germany, Brazil, and India, with one compromised French organization later weaponized to launch further spear-phishing attacks, borrowing its trusted reputation to target new victims.

The campaign underscores Lazarus’ continued shift toward stealthier, infrastructure-abusing tradecraft that blends zero-day exploitation, SEO-driven malware distribution, and legitimate web servers to mask malicious traffic as normal network activity.

IOC CategoryIOC TypeValue
DLL Loader/DropperSHA-2562b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca8
DLL Loader/DropperSHA-2563a02d0d798e8d35555776886d92b20ff38a101c9ef7e0eebc8ce5d259516525a
DLL Loader/DropperSHA-25692106b0c62a0a42678232f8273f030b2d3c8e92efce81b98b9eec70cfe98afa1
DLL Loader/DropperSHA-256396192d92d17ace1a521f1351eeeba2825e60badd0d799cc5c338e4934b3c82c
DLL Loader/DropperSHA-256f7e620134ca935067797ab957317b346ce0df84a4e9b9ca54a6acc9b75afda4d
DLL Loader/DropperSHA-25675b93a7103b0562f6497d30052c0c5cf7aa58c1bf0e9297022b74469a7f096f1
DLL Loader/DropperSHA-256a45144d22cac70a45d71cf4dffa4efbc373658779a56cf1300d6ac863d6cc7e2
DLL Loader/DropperSHA-2561de949c71efcfb0ffc41f33d38833dbc4b082075b1a540fc68c18c535d7ad86c
DLL Loader/DropperSHA-2564c9b804d6155b29f1e27a9ffe531e10bc42a7bdab42f905b50146bf2026768d9
DLL Loader/DropperSHA-25629e24c007549e51319ff3aee011da6f9f93568e8c85a5ad69c9e53bd3f4533a2
DLL Loader/DropperSHA-2564ebdce2f47c23ff8c9e8e80c8b5239c7a5764da31cd3ab8f0505926890adc105
DLL Loader/DropperSHA-256c2aa28bb5e2a749c693712008276f311edd912f689371ef9e8a1ee5fb4167461
MISTPENSHA-2562db25ac41a66aa523c79e23e00443573530dd7bd82b8371bcc87bd7232e141eb
MISTPENSHA-2565278ee922838352f1480a73e971161017d643a80b7ec22bf725897dfd088696d
MISTPENSHA-256b4082d21070d9ddf53fde4ea22524d09e41ec9826ce63cef3c6235e458d21afb
MISTPENSHA-256fb3fc5626f68677fb1269a2fefbe70e719211b4065e836ab92e06a8210139a2d
MISTPENSHA-256ea7056f2bf36c66a61ff787ff5be975a85f534c3c5ca178791dac2504db2c619
MISTPENSHA-25613d10bc99f7f7abe7ee0902be87920b73b2ea41bd9683dbfcad340dacbcdef79
MISTPENSHA-2564fd32432341dfcf54d0517a6bbc38e5d265be70933493e4183c2a340cdde9a2d
MISTPENSHA-2564dd792c9f672bbdcc8d363d745994efe90f4ffc5fdc2c059c8e379a48ad6a68a
MISTPENSHA-256ba96c603e44046de703c67b2c3b7e4ca974afef7b437a0244418bc4edc781bb7
ForestTigerSHA-25672dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289
ForestTigerSHA-256231b1ef8b95bf77887d5377e2a60f649035e78f543af1b82877db36a5759d858
ForestTigerSHA-2566da9b1e6f3315ceb77dd14a937a26cc3602bf6a7e2c2ecafb3c65ce5319837be
ForestTigerSHA-256a0578a2b7821d7e2c573530648f26d7a0d98b373ab24fb7f0c792736761e542d
ForestTigerSHA-25682268052f94df6f4870d02e57b18d4c54136cc7a8c8d80ad162631f99462c943
FudModuleSHA-2563b6378df8442e63a6ed7317075913e4720847a510d95022d4a8347b2637c245d
PDF PayloadSHA-256a673ae661593c0de9bbb815593b816a6853dad6d55ad5042d2ef1875cd13d6e7
PDF PayloadSHA-2568ce6c29f92dc45b1474417cbdff4ed0c18e58fa63e3a071ee9f85aa9d2aac07c
PDF PayloadSHA-256acb97cec84e08b89f41967a24e965d1fd2c51751cef158f7aa35bb4306b87b97
PDF PayloadSHA-2563601060c62edeeaa49def6a13be6e126e1024ce011faad4e2d9f585ccf6bd5a6
PDF PayloadSHA-256fecf12088843801215898442bd1ff3e266f29d14e29a94780e857f69c4915d6b
PDF PayloadSHA-256d578c28c9afe7457a0d81f6701332ef8197e8f7468de654935fb29a50ea66459
SecurityPDF.exeSHA-256743172aab606974b054a64561534ae66baa3a840657f79d7c6fa18350e8d45d1
SecurityPDF.exeSHA-256db3d69b7eeda2e35e23006bf4b7e206281fce809584207214fc213f9bc30376d
Troy BackdoorSHA-256590fb6ae19480d694e08ee85859cad8066f2f87e7e5abba2960c6d115e1615d6
Troy BackdoorSHA-25668d4fba7b1300a59cd6212c08910a260cd71b40cd9f51cac933030a68faac0bb
Troy BackdoorSHA-256a738059ce07c951c31ab2da3d93d8f69bff32f9b7d933dbf5943441b9cc99075
RelayShellSHA-25621c3ad4838c4324bc5f081021da5fb2e9073d0c9304087811c21eb47c9e22762
RelayShellSHA-256cc4e06aa378a190f71384c03023bb3d18a6d66e297d46701220e132963d2e222
SecurityPDF Website / Troy C2Domainenvell[.]xyz
SecurityPDF Website / Troy C2Domainenveil[.]online
SecurityPDF Website / Troy C2Domainuxtramine[.]org
SecurityPDF Website / Troy C2IPv4 address135.181.67[.]203

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN. Gain complete phishing visibility to strengthen your SOC and reduce MTTR   

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories