THE Lazarus group, linked to North Korea, launched a campaign called Operation Dream Job, targeting defense and aerospace companies in Europe and India. The campaign utilized spear-phishing and a Windows zero-day vulnerability (CVE-2026-68820) to deliver a trojanized PDF viewer, enabling further backdoor access. Microsoft patched the vulnerability on August 11, 2026.
The attackers exploited compromised servers to enhance phishing credibility, affecting multiple countries and employing at least 17 relay nodes for command and control. Urgent patching and email verification are recommended for protection.