The North Korea-linked Lazarus Group expanded its long-running Operation DreamJob espionage campaign by using recruiter-themed lures, impersonation sites, and trojanized PDF software to compromise defense, aerospace, aviation, and UAV-related organizations in Europe, India, and other regions. Researchers said victims were sent tailored job descriptions through email, messaging platforms, and password-protected archives, then tricked into opening decoy documents with modified PDF readers that delivered malware including ScoringMathTea, MISTPEN, ForestTiger, and related loaders. ESET and Mandiant linked the activity to cyberespionage and theft of proprietary technology, with particular interest in drone manufacturing know-how and other sensitive defense-sector information.
Check Point reported that the campaign escalated access by exploiting CVE-2026-68820, a zero-day local privilege escalation flaw in Microsoft AFD.sys, to deploy the FudModule rootkit with SYSTEM privileges and reduce endpoint detection visibility; Microsoft patched the issue on August 11, 2026. The operation also abused vulnerable Roundcube servers via CVE-2025-49113 and installed the RelayShell PHP webshell to convert compromised web servers into command-and-control relay nodes, while compromised organizations were reused to spear-phish additional targets. Across the reporting, Lazarus showed a consistent pattern of evolving DreamJob tradecraft through trojanized open-source software, encrypted payload staging, DLL proxying, and use of trusted third-party infrastructure to improve stealth and credibility.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
24 events from the most recent confirmed update back to the earliest known activity.
After Microsoft patched CVE-2026-68820, CISA added the Windows AFD.sys zero-day to its Known Exploited Vulnerabilities catalog and directed federal agencies to remediate it within two weeks. The action followed reporting that Lazarus had exploited the flaw in Operation DreamJob attacks.
Check Point said Lazarus exploited CVE-2026-68820, a zero-day use-after-free vulnerability in the Windows AFD.sys driver, during Operation Dream Job intrusions. Microsoft patched the flaw on August 11, 2026.
Check Point reported that Lazarus deployed a new FudModule v3.1 rootkit after exploiting CVE-2026-68820 in Operation DreamJob attacks. The upgraded variant broadened its security-evasion features by blinding more than 90 ETW providers, suppressing security products generically, and tampering with Smart App Control state.
Check Point reported that the investigated FudModule sample Afd4Eop12_x64.dll carried a compiler timestamp of July 7, 2026, 22:07:44 UTC. The sample was used in Lazarus intrusions to exploit a Windows local privilege escalation flaw and run with SYSTEM privileges.
Check Point observed a second infection chain in July 2026 using SecurityPDF, a trojanized MuPDF-based viewer, and an encrypted PDF payload. The chain decrypted and launched new.exe, which reflectively loaded a DLL containing the newly identified Troy backdoor.
Check Point reported that at least one compromised organization headquartered in France was subsequently leveraged by Lazarus to conduct spear-phishing attacks against additional targets worldwide. This showed the attackers reusing an earlier victim's infrastructure and reputation to improve the credibility of follow-on DreamJob lures.
ESET telemetry observed ScoringMathTea used against an Italian aerospace company in September 2025. The victim fit the campaign's emphasis on aerospace and UAV-related targets.
ESET reported an August 2025 VirusTotal submission from Spain containing BinMergeLoader. The loader was built from trojanized WinMerge plugins and tied to the same Lazarus activity cluster.
ESET observed a new wave of Operation DreamJob activity beginning in late March 2025. The campaign targeted three European defense-sector companies, including organizations involved in UAV-related manufacturing and software.
ESET reported VirusTotal submissions from Italy in April and June 2025 involving a trojanized MuPDF reader, QuanPinLoader, a dinput.dll loader, and a ScoringMathTea variant. These submissions reflected components used in the 2025 DreamJob wave.
On 2024-08-19, Microsoft identified a North Korean threat actor it tracks as Citrine Sleet exploiting CVE-2024-7971 in Chromium to target primarily cryptocurrency organizations. The attack chain used a malicious lure domain, chained CVE-2024-38106 for sandbox escape, and deployed the FudModule rootkit, showing shared tooling with other North Korean actors.
Researchers discovered in early June 2024 that Lazarus Group was exploiting CVE-2024-38193, a use-after-free flaw in the Windows AFD.sys driver, to gain kernel read/write access and deploy FudModule v3.0. The campaign targeted sensitive sectors including aerospace and cryptocurrency engineering and showed the rootkit had evolved into a loader/protector for additional payloads.
Later in June 2024, Mandiant discovered additional UNC2970 phishing lures masquerading as an energy company and an aerospace entity. The campaign delivered password-protected ZIP archives containing an encrypted PDF and a trojanized SumatraPDF that deployed MISTPEN via BURNBOOK.
In June 2024, Mandiant Managed Defense identified a suspected North Korea–nexus espionage cluster tracked as UNC2970. The actor used recruiter-themed job lures to target victims in U.S. critical infrastructure sectors.
Avast published research on Lazarus Group's FudModule rootkit, describing the malware and its use of an admin-to-kernel zero-day to move beyond BYOVD techniques. This represents an earlier public disclosure of the rootkit than the later 2024 exploitation reports already in the timeline.
ESET noted that Microsoft publicly documented ScoringMathTea in October 2023 under the name ForestTiger. This linked separate vendor tracking to the same Lazarus-associated malware.
ESET telemetry showed ScoringMathTea being used against a British industrial automation company in October 2023. The case extended the malware's observed victimology beyond defense firms alone.
ESET said ScoringMathTea was publicly documented by Kaspersky in April 2023. This marked one of the first public disclosures of the malware family.
ESET reported seeing ScoringMathTea used against a Polish defense company in March 2023. The activity fit the broader Operation DreamJob pattern attributed to Lazarus.
ESET telemetry recorded ScoringMathTea being used against an Indian technology company in January 2023. This was one of the earlier observed deployments of the RAT in DreamJob-related activity.
ESET traced the first appearance of the ScoringMathTea RAT to late 2022, when its dropper was uploaded to VirusTotal. The malware later became a recurring payload in Operation DreamJob activity.
A 2022 Virus Bulletin conference paper publicly documented Lazarus Group's use of bring-your-own-vulnerable-driver techniques to gain kernel-level access on Windows systems. This represents an earlier public disclosure of Lazarus Windows-core abuse preceding later reporting on FudModule and related zero-day exploitation.
ClearSky reported in August 2020 on a widespread campaign it called Dream Job, which it attributed with high probability to North Korea's Lazarus Group and said had been active since the beginning of 2020. The operation targeted defense and government-related organizations in Israel and globally using fake recruiter personas and job offers from major U.S. defense and aerospace firms.
Check Point disclosed that Lazarus routed command-and-control traffic through compromised Roundcube, WordPress, and PrestaShop sites, including Roundcube servers vulnerable to CVE-2025-49113. The researchers identified a new PHP relay web shell called RelayShell and at least 17 unique compromised relay nodes used in the campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcebsky.app
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourcevirusbulletin.com
Open sourcemsrc.microsoft.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.