Lazarus Group Uses Windows Zero-Day and Fake Job Offers to Backdoor Defense Firms
North Korea-linked Lazarus Group has been running 'Operation Dream Job', targeting defense and aerospace personnel with fake job offer PDFs to deliver a multi-stage malware chain, according to Check Point Research published on August 11, 2026. Victims are tricked into running a signed PDF viewer that side-loads a malicious DLL, which silently executes the MISTPEN backdoor in memory while displaying a decoy document. MISTPEN communicates with attacker-controlled servers via Microsoft Graph API and OneDrive, before exploiting a critical Windows 11 kernel zero-day, CVE-2026-68820, to gain SYSTEM privileges and disable endpoint detection tools using the FudModule rootkit. The final payload, a backdoor called ForestTiger, is then deployed alongside the Troy backdoor, which supports 17 command types including file transfer, process reconnaissance, and in-memory DLL injection. Attackers also compromised Roundcube mail servers by exploiting CVE-2025-49113 to install the RelayShell web shell, using them as traffic relays to obscure command-and-control infrastructure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in