THE North Korean Lazarus Group has launched a new phase of its long-running 'Operation Dream Job,' targeting defense and aerospace professionals with fake job offers that exploit a recently discovered Windows zero-day vulnerability, identified as CVE-2026-68820. This zero-day allows attackers to gain full control of infected machines and evade security measures, leveraging hijacked legitimate websites for command infrastructure.
The attack features two infection chains: one delivering a malicious DLL through a trojanized PDF viewer that loads a backdoor known as ForestTiger, and another inducing users to download a compromised viewer named SecurityPDF, which embeds a new backdoor called Troy. Security teams are advised to apply the recent Microsoft patch and review indicators of compromise to safeguard against these attacks.