THE article by Check Point Research details a significant cyber attack campaign named **Operation Dream Job**, attributed to the DPRK-linked **Lazarus group**. The campaign particularly targets organizations in the defense sector across Europe and India, utilizing a malicious PDF viewer called **SecurityPDF** to distribute a backdoor called **Troy**.
Key exploits used include **CVE-2026-68820**, a zero-day vulnerability in Microsoft's **AFD.sys** driver, and **CVE-2025-49113** affecting **Roundcube** webmail servers. The attack chain primarily involves spear-phishing, where attackers pose as recruiters offering job opportunities, convincing victims to download malicious files.
The malware employed includes the **MISTPEN** downloader and **FudModule**, a kernel-mode rootkit, escalated privileges, and deployed the **ForestTiger** backdoor with a resilient command-and-control infrastructure leveraging compromised Roundcube servers. Overall, the research emphasizes the evolving tactics of Lazarus, showcasing their ability to blend malicious activity with legitimate web operations, reflecting a trend towards stealthier cyber operations in critical sectors.