SecurityPDF is a trojanized Windows PDF viewer used by the Lazarus Group in Operation Dream Job to target defense-sector organizations, particularly aerospace and aviation entities in Europe and India. It has been distributed through fake job-offer lures, impersonation websites, and search-engine optimization designed to make malicious downloads appear legitimate.
The malware is a modified PDF reader built from the MuPDF framework. Its core purpose is to open attacker-crafted PDF documents and inspect them for a hidden marker indicating that an embedded payload should be activated. When the marker is present, SecurityPDF decrypts and launches a loader that reflectively loads the Troy backdoor directly into memory. This behavior makes SecurityPDF an execution vehicle for follow-on malware rather than a standalone espionage implant.
In observed intrusions, SecurityPDF served as one infection chain within a broader Lazarus operation that also involved social engineering, post-compromise privilege escalation, and deployment of additional tooling. The associated Troy implant provides modular backdoor functionality including reconnaissance, file operations, command execution, exfiltration, process control, and in-memory DLL injection. Campaign reporting also links the wider intrusion set to exploitation of CVE-2026-68820 for SYSTEM-level privilege escalation and deployment of Lazarus tooling such as FudModule, although those actions are attributable to the broader operation rather than to SecurityPDF alone.
SecurityPDF is best characterized as a trojanized application used for initial execution of Lazarus payloads on victim Windows systems. Its use against defense and aerospace targets aligns with espionage-focused objectives historically associated with Operation Dream Job.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Today, August 25, 2026, is the CISA KEV deadline requiring all Federal Civilian Executive Branch agencies to patch CVE-2026-68820, the underlying Windows WinSock driver flaw that ShieldBreak (CVE-2026-69414) bypasses. Check Point Research this week formally attributed exploitation of CVE-2026-68820 to North Korea's Lazarus Group as part of Operation Dream Job, where the group distributed a malicious PDF viewer called SecurityPDF to aerospace and defence targets alongside fake job offer lures, using the driver flaw to escalate from initial access to full SYSTEM privileges. | Lazarus Group as part of Operation Dream Job, where the group distributed a malicious PDF viewer called SecurityPDF to aerospace and defence targets alongside fake job offer lures, using the driver flaw to escalate from initial access to full SYSTEM privileges.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lazarus Group as part of Operation Dream Job, where the group distributed a malicious PDF viewer called SecurityPDF to aerospace and defence targets alongside fake job offer lures, using the driver flaw to escalate from initial access to full SYSTEM privileges.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
распространяли модифицированный PDF-ридер SecurityPDF, который предназначался для выполнения малвари, встроенной в заранее подготовленные хакерами PDF-файлы.
Lazarus Group as part of Operation Dream Job, where the group distributed a malicious PDF viewer called SecurityPDF to aerospace and defence targets alongside fake job offer lures, using the driver flaw to escalate from initial access to full SYSTEM privileges.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious PDF viewer used by Lazarus Group in Operation Dream Job to gain initial access to targets, after which the attackers exploited a Windows driver flaw for privilege escalation.
Modified PDF reader used as part of Lazarus's Operation Dream Job campaign to execute malware embedded in attacker-prepared PDF files.
A trojanized PDF viewer used as a delivery mechanism to execute the Troy backdoor in memory when specially marked PDF files are opened.
A modified PDF viewer used as a trojanized delivery mechanism to execute malicious payloads embedded in attacker-crafted PDF files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.