The notorious Lazarus Group, a cyber-threat entity linked to North Korea, has been identified as exploiting a recently patched vulnerability in Microsoft Windows to infiltrate global defense and aerospace sectors. This intrusion involves a sophisticated backdoor, reflecting the group’s ongoing cyber espionage efforts targeting companies in France, Germany, Brazil, and India.
Operation Dream Job’s Deceptive Tactics
According to research by Check Point, this attack is part of the larger Operation Dream Job, a deceitful campaign that leverages fake job offers to mislead professionals into revealing sensitive information. The Lazarus Group employs social engineering on platforms like LinkedIn, posing as recruiters from credible companies such as Lockheed Martin, to gain victims’ trust and plant malware.
The group exploits a vulnerability identified as CVE-2026-68820, a privilege escalation flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys), which Microsoft addressed in its August 2026 security updates.
Technical Details of the Exploit
The attack involves luring individuals into opening malicious PDFs or using a compromised PDF viewer, resulting in the installation of a novel backdoor named ‘Troy’. This backdoor facilitates remote access, enabling attackers to seize control of the targeted systems and circumvent security measures.
The Lazarus Group continues to utilize a trojanized PDF viewer strategy, dating back to 2022. Recent attacks have revealed two infection pathways: DLL side-loading and a trojanized PDF viewer, each with specific techniques to evade detection and maintain persistence.
Advanced Infection Techniques
In the DLL side-loading approach, victims are tricked into downloading an encrypted archive, initiating a chain that leads to the execution of MISTPEN. This downloader communicates with attacker-controlled infrastructures, such as Microsoft Graph API and OneDrive, to deploy reconnaissance and persistence modules before exploiting the ‘AFD.sys’ vulnerability.
Alternatively, the trojanized PDF viewer, masquerading as SecurityPDF, uses a special marker to activate a payload that deploys the Troy backdoor. This setup supports a range of commands for data exfiltration and system manipulation.
Implications and Defense Measures
The campaign utilizes legitimate-looking websites to distribute SecurityPDF, leveraging compromised WordPress and SharePoint sites as command-and-control servers. This tactic complicates detection, as it blends malicious activity with normal web traffic. The attackers also exploit vulnerabilities in Roundcube servers to deploy a PHP web shell for command exchange.
Despite these challenges, cybersecurity experts stress the importance of maintaining updated systems and verifying software authenticity through official channels, as emphasized by Sergey Shykevich of Check Point Software. He warns that the sophistication of this campaign lies in its ability to integrate with trusted infrastructure, urging organizations to adopt a zero-trust approach even with seemingly legitimate entities.
