Recent reports by Check Point reveal that North Korean hackers have been leveraging a freshly patched Windows zero-day vulnerability to compromise systems. This cyberattack is attributed to the notorious Lazarus Group, known for its persistent targeting of job seekers with deceptive employment offers.
The Operation Dream Job Campaign
Continuing their Operation Dream Job initiative, these hackers have been active since early 2026, focusing on the defense industry, particularly aerospace and aviation sectors in Europe and India. The attackers masquerade as recruiters, using professional networking sites and messaging apps to lure victims into downloading malicious software.
Infection Techniques and Exploits
One infection method involves distributing an archive containing a PDF viewer, a harmful DLL, and a payload disguised as a PDF file. Through DLL sideloading, the Mistpen malware downloader is executed, displaying a fake job description while initiating malicious activities.
The attack sequence advances through reconnaissance and persistence, exploiting a zero-day in Windows’ Ancillary Function Driver (afd.sys), now identified as CVE-2026-68820. This vulnerability allows attackers to gain System privileges via a race condition.
Mitigation and Future Outlook
Microsoft addressed this vulnerability on August 11 during its Patch Tuesday updates. The US cybersecurity agency CISA has since urged federal agencies to apply this patch swiftly. Another infection path involves a trojanized PDF viewer, SecurityPDF, which activates the Troy backdoor to execute multiple commands.
Check Point also observed compromised infrastructures, including Roundcube webmail and CMS platforms affected by CVE-2025-49113. These systems are infiltrated with RelayShell, a PHP webshell, facilitating communication between infected systems and attackers.
Organizations in the defense, aerospace, and aviation sectors in France, Germany, Brazil, and India have been primary targets. Check Point advises prioritizing the August Patch Tuesday update and scrutinizing unverified recruitment communications to mitigate risks.
