The North Korea-linked Lazarus group is utilizing pretend job gives, trojanized PDF software program and a Home windows zero-day in assaults aimed primarily on the protection sector, Examine Level researchers have discovered.
The exercise is a part of Operation Dream Job, a long-running marketing campaign through which attackers pose as recruiters and lure targets with job alternatives at well-known firms. One of many decoy paperwork uncovered throughout the investigation used a Lockheed Martin job description.
Examine Level was unable to find out how victims had been first approached. Based mostly on earlier Dream Job operations, they assess that Lazarus seemingly contacted targets by skilled networking platforms reminiscent of LinkedIn or by messaging purposes.
“Posing as recruiters, the attackers current engaging job alternatives and in the end direct victims to obtain malicious recordsdata,” the researchers famous.
Lazarus exploits Home windows zero-day to realize SYSTEM privileges
Researchers recognized two an infection chains working in parallel. Within the first, the sufferer is satisfied to obtain an encrypted ZIP archive containing three recordsdata:
- A respectable, digitally signed PDF viewer executable
- A malicious DLL loaded by DLL sideloading
- An encrypted payload with a PDF extension

Excessive-level overview of the DLL sideloading an infection chain (Supply: Examine Level)
“When the sufferer launches the executable, the malicious DLL libmupdf.dll is loaded by way of DLL sideloading. The DLL extracts a decoy PDF doc from the encrypted payload and shows it to the person, whereas concurrently extracting, decrypting, and executing an embedded payload immediately in reminiscence,” the researchers defined.
The malware then runs MISTPEN, an in-memory downloader that profiles the compromised system and retrieves further elements.
A type of elements exploits CVE-2026-68820, an area privilege escalation vulnerability within the Home windows AFD.sys driver. Profitable exploitation offers the attackers SYSTEM privileges and lets them deploy FudModule, a Lazarus kernel-mode rootkit constructed to intervene with safety monitoring.
Researchers examined the exploit towards an up to date Home windows 11 system and decided that it focused a beforehand unknown vulnerability that had been exploited in Operation Dream Job since at the very least early July.
Examine Level reported the vulnerability to Microsoft, which patched it on August 11, 2026, as a part of its Patch Tuesday updates.
Trojanized PDF viewer delivers new backdoor
A second an infection chain, detected in July, shares traits with Operation Dream Job activity documented by ESET in 2025.
On this chain, the attackers despatched fraudulent job gives impersonating privateness know-how firm Enveil and instructed targets to obtain SecurityPDF, a modified model of an open-source PDF viewer.
When an attacker-prepared PDF is opened with SecurityPDF, the appliance extracts and executes an embedded payload. The payload installs Troy, a newly documented backdoor that offers the attackers distant entry to the compromised system.
The attackers created at the very least three web sites impersonating Enveil to distribute SecurityPDF. Some ranked excessive in search outcomes, together with as the highest end result for related searches, based on Examine Level, who discovered no indication that Enveil itself was focused or compromised.
“Though we didn’t immediately observe how the menace actor integrated these web sites into the phishing marketing campaign, we assess that they had been seemingly used to separate the supply of the trojanized PDF viewer from the supply of the crafted PDF doc,” they added.
“On this state of affairs, victims would first obtain the malicious PDF file by a phishing message and later be instructed to obtain the PDF viewer from what seems to be the seller’s respectable web site.”
Compromised servers used for attacker visitors
Lazarus additionally compromised Roundcube webmail and different net servers and used them to relay command-and-control visitors.
Researchers discovered that a number of compromised Roundcube servers had been working variations susceptible to CVE-2025-49113. They assess that stolen credentials could have been used to authenticate to the servers earlier than exploiting the vulnerability and deploying RelayShell, a beforehand undocumented PHP net shell.
Operation Dream Job expands worldwide
The marketing campaign centered totally on organizations in Western Europe and India, with exercise extending to South America.
In at the very least one case, the attackers compromised a company headquartered in France and used it to ship spear-phishing messages to further targets.
“The most recent Operation Dream Job marketing campaign demonstrates that Lazarus continues to evolve each its malware capabilities and operational tradecraft,” Examine Level concluded.
Sandworm hackers goal IT professionals
One other state-sponsored menace actor can also be after job seekers. Ukraine’s CERT-UA has individually documented the same tactic utilized by UAC-0145, a subcluster of the Russian state-linked Sandworm group, additionally tracked as APT44 and Seashell Blizzard. In that marketing campaign, energetic since at the very least Could 2026, attackers goal system directors and IT professionals by pretend job gives.