Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack (opens in a new tab)
Why readLazarus burned a Windows AFD.sys zero-day (CVE-2026-68820, patched in August Patch Tuesday) to load a new FudModule rootkit build, alongside a Roundcube RCE and a new backdoor named Troy.
Check Point tracks the latest Operation Dream Job wave against defence organisations in Europe and India, delivered through SecurityPDF, a modified PDF viewer that opens attacker-crafted documents and drops a previously undocumented backdoor called Troy. The intrusion used CVE-2026-68820, a zero-day in the Microsoft AFD.sys driver, to deploy an updated version of Lazarus' kernel-mode FudModule rootkit; Microsoft patched it in the August 2026 Patch Tuesday after Check Point's disclosure. The actor also exploited CVE-2025-49113 (EPSS 0.98) against Roundcube webmail servers, planting a PHP webshell named RelayShell that turns those hosts into C2 relay nodes.
Indicators17
- Hashes
2b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca83a02d0d798e8d35555776886d92b20ff38a101c9ef7e0eebc8ce5d259516525a92106b0c62a0a42678232f8273f030b2d3c8e92efce81b98b9eec70cfe98afa1396192d92d17ace1a521f1351eeeba2825e60badd0d799cc5c338e4934b3c82cf7e620134ca935067797ab957317b346ce0df84a4e9b9ca54a6acc9b75afda4d75b93a7103b0562f6497d30052c0c5cf7aa58c1bf0e9297022b74469a7f096f1a45144d22cac70a45d71cf4dffa4efbc373658779a56cf1300d6ac863d6cc7e21de949c71efcfb0ffc41f33d38833dbc4b082075b1a540fc68c18c535d7ad86c4c9b804d6155b29f1e27a9ffe531e10bc42a7bdab42f905b50146bf2026768d929e24c007549e51319ff3aee011da6f9f93568e8c85a5ad69c9e53bd3f4533a24ebdce2f47c23ff8c9e8e80c8b5239c7a5764da31cd3ab8f0505926890adc105c2aa28bb5e2a749c693712008276f311edd912f689371ef9e8a1ee5fb4167461- Addresses
135[.]181[.]67[.]203135[.]181[.]185[.]158- Domains
envell[.]xyzenveil[.]onlineuxtramine[.]org