research.checkpoint.com 8/11/2026, 5:51:11 PM · external

Lazarus hits defence via fake job PDFs, CVE-2026-68820

Lazarus hits defence via fake job PDFs, CVE-2026-68820
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor

THE article by Check Point Research details a significant cyber attack campaign named **Operation Dream Job**, attributed to the DPRK-linked **Lazarus group**. The campaign particularly targets organizations in the defense sector across Europe and India, utilizing a malicious PDF viewer called **SecurityPDF** to distribute a backdoor called **Troy**.

Key exploits used include **CVE-2026-68820**, a zero-day vulnerability in Microsoft's **AFD.sys** driver, and **CVE-2025-49113** affecting **Roundcube** webmail servers. The attack chain primarily involves spear-phishing, where attackers pose as recruiters offering job opportunities, convincing victims to download malicious files.

The malware employed includes the **MISTPEN** downloader and **FudModule**, a kernel-mode rootkit, escalated privileges, and deployed the **ForestTiger** backdoor with a resilient command-and-control infrastructure leveraging compromised Roundcube servers. Overall, the research emphasizes the evolving tactics of Lazarus, showcasing their ability to blend malicious activity with legitimate web operations, reflecting a trend towards stealthier cyber operations in critical sectors.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline