Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

North Korean Lazarus Group Unleashes Operation Dream Job: A Sophisticated Campaign of Social Engineering and Exploitation



The North Korean Lazarus Group has launched a new operation dubbed "Operation Dream Job," utilizing a previously unknown Windows zero-day vulnerability to gain full control of infected computers. The campaign targets defense and aerospace professionals with fake job offers, employing a sophisticated combination of social engineering and exploitation tactics.

  • The North Korean Lazarus Group has launched a new operation called "Operation Dream Job" using a previously unknown Windows zero-day vulnerability.
  • The operation uses fake job offers to lure defense professionals into downloading malware, including MISTPEN and ForestTiger backdoors.
  • A second chain of infection uses a trojanized PDF viewer to launch the Troy backdoor directly into memory.
  • The attack employs a relay network using compromised webmail installations and WordPress sites, with operators connecting through VPNs to obscure their location.
  • Security teams are advised to prioritize the August Patch Tuesday update and review indicators of compromise for this operation.



  • The North Korean Lazarus Group, a notorious cyber threat actor known for its sophisticated campaigns targeting defense and aerospace professionals, has recently launched a new operation dubbed "Operation Dream Job." This operation marks a significant escalation in the group's tactics, utilizing a previously unknown Windows zero-day vulnerability to gain full control of infected computers and evade security controls.

    According to Check Point Research, a leading cybersecurity firm, Operation Dream Job involves the use of fake job offers from reputable companies like Lockheed Martin, which serve as a lure for defense professionals. Once victims download an encrypted archive containing a legitimate signed PDF viewer and a malicious DLL, they are tricked into installing MISTPEN, a lightweight downloader that communicates through Microsoft Graph API and OneDrive. This installer then loads reconnaissance modules, triggers the AFD.sys exploit to achieve SYSTEM privileges, and deploys ForestTiger, a well-documented Lazarus backdoor.

    The attack also employs a second chain of infection, where victims are instructed to download SecurityPDF, a trojanized PDF viewer, from websites impersonating Enveil, a legitimate privacy technology company. Once installed, the modified viewer inspects any PDF opened through it for a hidden marker and launches an embedded payload that loads the Troy backdoor directly into memory.

    Troy is a single DLL implant that supports 17 operator commands covering file operations, shell access, process termination, in-memory DLL injection, and configuration updates. Its name comes from a PDB path embedded in the binary that Check Point also observed in earlier Lazarus samples. Enveil has no connection to the campaign; its brand was simply borrowed because it sounds credible to defense sector professionals.

    The C2 infrastructure built by the attackers is comprised of compromised Roundcube webmail installations and WordPress sites, many vulnerable to CVE-2025-49113, infected with a previously undocumented PHP webshell called RelayShell. RelayShell functions as a relay rather than a traditional backdoor, exchanging commands and responses through simple text files.

    In at least one confirmed case, an already-breached French organization was used to send phishing messages to new victims — the attackers borrowed the company’s reputation to get past filters. Check Point identified at least 17 unique server identifiers in this relay network, with operators connecting through commercial VPNs to further obscure their location.

    Given the combination of a zero-day vulnerability that now has a patch, a new modular backdoor, and web-based infrastructure designed to resemble legitimate traffic, security teams in these sectors should prioritize the August Patch Tuesday update, review the indicators of compromise published in Check Point Research publication, and apply the same level of scrutiny to unsolicited recruiting outreach that they would apply to any unverified download request.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/North-Korean-Lazarus-Group-Unleashes-Operation-Dream-Job-A-Sophisticated-Campaign-of-Social-Engineering-and-Exploitation-ehn.shtml

  • https://securityaffairs.com/197098/uncategorized/north-korean-lazarus-group-uses-windows-zero-day-in-operation-dream-job.html

  • https://www.bleepingcomputer.com/news/security/lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms/

  • https://nvd.nist.gov/vuln/detail/CVE-2025-49113

  • https://www.cvedetails.com/cve/CVE-2025-49113/

  • https://socprime.com/blog/cve-2026-68820-actively-exploited-windows/

  • https://cybersecuritynews.com/windows-afd-sys-zero-day-exploited/


  • Published: Thu Aug 13 02:33:49 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us