Lazarus Operation Dream Job Profile: Windows Zero-Day and Troy Backdoor in a Fake Recruitment Campaign

Lazarus Group used fake recruitment lures, a Windows zero-day, the Troy backdoor, MISTPEN and FudModule 3.1 in a renewed Operation Dream Job campaign.

Operation Dream Job once again shows why fake recruitment remains one of the most dangerous cyber espionage scenarios. According to The Hacker News, citing analysis from Check Point Research, the North Korea-linked Lazarus Group exploited a Windows flaw recently patched by Microsoft to escalate privileges to SYSTEM, then deployed a new backdoor called Troy against targets in the defense and aerospace sectors in France, Germany, Brazil and India.

The notable point is not only that Lazarus used a zero-day. The campaign also combines several familiar techniques in a refreshed chain: recruitment lures on professional platforms, a trojanized PDF viewer, DLL side-loading, command infrastructure hidden behind compromised WordPress, SharePoint and Roundcube services, and a new version of the FudModule rootkit capable of interfering with Windows protection mechanisms.

Context: fake recruitment as an espionage cover

Operation Dream Job is a long-running campaign in which Lazarus impersonates recruiters or representatives of major companies to approach engineers, technology specialists, defense personnel and aerospace professionals. The scenario often begins with an attractive job opportunity, convincing enough for the victim to open a job description document or download a document viewer supplied by the attacker.

In the latest wave, the lures used names with weight in the defense and technology sectors, including Lockheed Martin and Enveil. This approach exploits a very practical professional mindset: the recipient may be looking for a job, evaluating a new opportunity, or simply curious about an offer that appears legitimate.

CVE-2026-68820 and the goal of privilege escalation

The exploited vulnerability is CVE-2026-68820, a CVSS 7.0 flaw in the Windows Ancillary Function Driver for WinSock, commonly known as AFD.sys. Microsoft fixed the issue in the August 2026 Patch Tuesday update. Successful exploitation allows malware to locally escalate privileges to SYSTEM, a highly privileged level on Windows systems.

For an espionage campaign, SYSTEM privileges help attackers bypass ordinary limits: maintain persistence for longer, run payloads in more trusted processes, disable or evade some protection mechanisms and collect data deeper inside the system. Even though the flaw requires code execution on the machine first, it becomes highly dangerous when paired with a social engineering chain such as Dream Job.

Diagram of the Lazarus Operation Dream Job infection chain using DLL side-loading and a fake PDF viewer

Two parallel infection paths

The Hacker News reports that Check Point observed at least two infection chains running in parallel in the new campaign.

The first path uses DLL side-loading. Victims are instructed to download an encrypted archive. When opened, the execution chain triggers a malicious DLL named libmupdf.dll. This component displays a fake job description document to distract the user while silently loading and running a lightweight downloader named MISTPEN in memory. MISTPEN communicates with attacker infrastructure through the Microsoft Graph API and OneDrive to retrieve reconnaissance modules, persistence components and the AFD.sys exploitation component.

The second path uses a fake PDF viewer named SecurityPDF. Victims are directed to an Enveil-themed impersonation website to download the tool. Once installed, SecurityPDF monitors PDF documents opened through it. If a document contains a special marker, the application decrypts and loads the embedded payload, bringing the Troy backdoor into memory.

Troy, MISTPEN and FudModule 3.1

The Troy backdoor supports multiple operational command groups, including file listing, data upload and download, file compression and theft, interactive shell access, process termination, in-memory DLL loading and configuration updates. This capability set is sufficient to turn a compromised machine into a foothold for long-term espionage activity.

MISTPEN acts as an intermediate module loader. The modules mentioned include host information collection, process enumeration, full desktop screenshot capture and a loader used for privilege escalation. Notably, this loader uses the post-quantum ML-KEM key exchange mechanism during the handshake to decrypt and run FudModule.

FudModule is a kernel-mode rootkit previously used by Lazarus in several campaigns. The new version, described as FudModule 3.1, adds the ability to interfere with Smart App Control, a Windows feature designed to check the safety and reputation of applications before allowing them to run. This shows that Lazarus is not only exploiting new vulnerabilities, but also continuing to invest in operating system-level defense evasion.

Command infrastructure hidden behind legitimate services

Another important point is how Lazarus hides its command infrastructure. Instead of relying only on attacker-controlled servers that are easier to block, the group abuses compromised legitimate WordPress and SharePoint sites, as well as vulnerable Roundcube webmail servers. Some Roundcube servers were reportedly tied to CVE-2025-49113 and later implanted with a previously undocumented PHP web shell named RelayShell.

This operating model raises the difficulty for defenders. Traffic to a real WordPress or SharePoint site may look normal, while in reality it is being used as a command channel or data relay. In at least one case, a previously compromised organization in France was also abused to send phishing emails to new victims, helping the message pass reputation-based filtering.

Defensive lessons for organizations

The case shows that fake recruitment campaigns should not be treated as a risk only for human resources teams. In defense, aerospace, research, finance and high-technology sectors, technical staff are also direct targets. Organizations need to train users to recognize unusual recruitment approaches, limit the opening of documents from unverified sources and tightly control the installation of external document viewing tools.

On the technical side, the immediate priorities are deploying Microsoft security updates from August 2026, monitoring exploitation indicators related to AFD.sys, checking unusual SYSTEM-level processes, and watching traffic to OneDrive, the Microsoft Graph API and legitimate websites showing abnormal behavior. Internal and partner-operated WordPress, SharePoint and Roundcube servers should also be reviewed, because they can become relay infrastructure for a campaign without being the final target.

Operation Dream Job proves again that modern attacks rarely depend on a single flaw. Lazarus succeeds by combining human psychology, fake software, a zero-day, a rootkit and compromised infrastructure into one continuous chain. Effective defense must therefore combine awareness training, patch management, behavior detection and privilege control instead of relying on a single protective layer.

VNCyberS compiled from The Hacker News and Check Point Research

Liên hệ với chúng tôi

Email: [email protected]
Điện thoại: +84 903260277