<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/lazarus-group-s-operation-dream-job-used-a-windows-zero-day-to-target-defense-and-aerospace-firms-zmtph9qhb" -->

---
title: Lazarus Group&#x27;s Operation Dream Job used a Windows...
description: Check Point Research has exposed a new wave of Lazarus Group&#x27;s Operation Dream Job, targeting defense, aerospace, and aviation organizations in France,...
canonical: https://daily.dev/posts/lazarus-group-s-operation-dream-job-used-a-windows-zero-day-to-target-defense-and-aerospace-firms-zmtph9qhb
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Lazarus Group&#x27;s Operation Dream Job used a Windows zero-day to target defense and aerospace firms | daily.dev
og:description: Check Point Research has exposed a new wave of Lazarus Group&#x27;s Operation Dream Job, targeting defense, aerospace, and aviation organizations in France,...
og:url: https://daily.dev/posts/lazarus-group-s-operation-dream-job-used-a-windows-zero-day-to-target-defense-and-aerospace-firms-zmtph9qhb
og:image: https://api.daily.dev/og/posts/zmtpH9qHB.png
og:image:alt: Lazarus Group&#x27;s Operation Dream Job used a Windows zero-day to target defense and aerospace firms
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Lazarus Group's Operation Dream Job used a Windows zero-day to target defense and aerospace firms

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

Check Point Research has exposed a new wave of Lazarus Group's Operation Dream Job, targeting defense, aerospace, and aviation organizations in France, Germany, Brazil, and India. The campaign begins with spear-phishing via fake job offers and a trojanized PDF viewer (SecurityPDF, built on MuPDF). Once inside, attackers deploy MISTPEN (an in-memory downloader using Microsoft Graph API/OneDrive for C2), Troy (a new 64-bit modular backdoor with 17 commands), and a new FudModule rootkit exploiting CVE-2026-68820, a zero-day use-after-free race condition in Windows afd.sys that grants SYSTEM privileges and blinds EDR tools. The vulnerability was patched on August 11 Patch Tuesday. C2 infrastructure relies on compromised third-party servers — including Roundcube webmail (CVE-2025-49113), WordPress, and PrestaShop sites — where a PHP webshell called RelayShell turns legitimate websites into anonymous relay nodes. At least 17 compromised relay servers were identified.

## Content

Check Point Research has published details on a fresh round of Lazarus Group's long-running Operation Dream Job campaign, and this one comes with a genuinely nasty upgrade: a Windows zero-day exploit that let attackers grab SYSTEM privileges and blind EDR tools outright.

The target list reads like a who's who of sensitive industries - defense, aerospace, and aviation firms across France, Germany, Brazil, and India. The playbook is familiar Lazarus territory: spear-phishing emails dangling fake job offers, the kind of lure that's worked on this sector for years. What's changed is the malware chain behind it.

## The infection chain

Victims who took the bait ended up with a trojanized PDF viewer called SecurityPDF, built on top of the legitimate MuPDF library, often delivered through impersonation websites boosted with SEO poisoning so they'd surface in search results. From there, the campaign deployed:

- **MISTPEN**, an in-memory downloader that uses the Microsoft Graph API and OneDrive as its command-and-control channel - a nice way to hide malicious traffic inside normal-looking cloud service calls.
- **Troy**, a new 64-bit modular RAT supporting 17 commands, giving operators fairly granular control over compromised machines.
- A new version of the **FudModule rootkit**, which is where things get interesting.

## The zero-day

This FudModule variant exploited CVE-2026-68820, a use-after-free race condition in Windows' afd.sys driver, to escalate to SYSTEM privileges and disable EDR visibility. It works on both Windows 11 builds 26100 and 26200. Microsoft patched the bug in its August 11 Patch Tuesday release, so this was a genuine zero-day at the time Lazarus was using it - not a case of attackers exploiting an old, unpatched flaw.

Using a real Windows LPE zero-day against defense contractors is a step up even for a group with Lazarus's resources. It's a reminder that patch Tuesday isn't just routine maintenance - sometimes it's closing a hole that's already been used against real targets.

## Infrastructure: hijacked webmail and a webshell that isn't quite a webshell

For command-and-control infrastructure, the group leaned on compromised Roundcube webmail servers, breaking in via CVE-2025-49113, alongside hacked WordPress and PrestaShop sites. On those compromised sites, Check Point found a new PHP webshell dubbed RelayShell - though

## Questions this post answers

### What CVE did Lazarus Group exploit in the FudModule rootkit to gain SYSTEM privileges on Windows?

Lazarus Group exploited CVE-2026-68820, a zero-day use-after-free race condition in the Windows afd.sys driver. This vulnerability allowed the FudModule rootkit to escalate to SYSTEM privileges and disable EDR tooling. The flaw was patched on August 11 Patch Tuesday.

_Teams hardening Windows endpoints against kernel-level exploits track patch releases and threat intel like this on daily.dev._

### How did Lazarus Group's Operation Dream Job hide its C2 traffic to avoid network detection?

MISTPEN, the in-memory downloader used in Operation Dream Job, routes command-and-control traffic through Microsoft's Graph API and OneDrive, blending malicious communications with legitimate Microsoft traffic. Additionally, Lazarus compromised at least 17 third-party servers — including Roundcube webmail, WordPress, and PrestaShop sites — installing a PHP webshell called RelayShell to act as anonymous bidirectional relay nodes.

_Security engineers defending against nation-state C2 evasion techniques follow campaigns like Operation Dream Job on daily.dev._

### What is RelayShell and how was it used in the Lazarus Group Operation Dream Job campaign?

RelayShell is a PHP webshell deployed by Lazarus Group on compromised legitimate websites, including Roundcube webmail servers (via CVE-2025-49113), WordPress, and PrestaShop sites. Unlike a traditional command shell, it functions as a bidirectional relay node, turning compromised legitimate websites into anonymous middlemen for C2 traffic rather than exposing attacker-controlled infrastructure.

_Defenders investigating webshell-based relay infrastructure find threat breakdowns like this on daily.dev._

## Similar posts on daily.dev

- [Lazarus group targets European drone makers in new espionage campaign](https://daily.dev/posts/lazarus-group-targets-european-drone-makers-in-new-espionage-campaign-2vahjx90k) · CSO Online · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#windows](https://daily.dev/tags/windows), [#php](https://daily.dev/tags/php)

[View this post on daily.dev](https://daily.dev/posts/lazarus-group-s-operation-dream-job-used-a-windows-zero-day-to-target-defense-and-aerospace-firms-zmtph9qhb)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Lazarus Group's Operation Dream Job used a Windows zero-day to target defense and aerospace firms","url":"https://daily.dev/posts/lazarus-group-s-operation-dream-job-used-a-windows-zero-day-to-target-defense-and-aerospace-firms-zmtph9qhb","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/lazarus-group-s-operation-dream-job-used-a-windows-zero-day-to-target-defense-and-aerospace-firms-zmtph9qhb"},"datePublished":"2026-08-11T19:40:10.453Z","dateModified":"2026-08-12T15:44:04.202Z","description":"Check Point Research has exposed a new wave of Lazarus Group's Operation Dream Job, targeting defense, aerospace, and aviation organizations in France,...","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/lazarus-group-s-operation-dream-job-used-a-windows-zero-day-to-target-defense-and-aerospace-firms-zmtph9qhb","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,windows,php","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Lazarus Group's Operation Dream Job used a Windows zero-day to target defense and aerospace firms"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/lazarus-group-s-operation-dream-job-used-a-windows-zero-day-to-target-defense-and-aerospace-firms-zmtph9qhb#faq","mainEntity":[{"@type":"Question","name":"What CVE did Lazarus Group exploit in the FudModule rootkit to gain SYSTEM privileges on Windows?","acceptedAnswer":{"@type":"Answer","text":"Lazarus Group exploited CVE-2026-68820, a zero-day use-after-free race condition in the Windows afd.sys driver. This vulnerability allowed the FudModule rootkit to escalate to SYSTEM privileges and disable EDR tooling. The flaw was patched on August 11 Patch Tuesday. Teams hardening Windows endpoints against kernel-level exploits track patch releases and threat intel like this on daily.dev."}},{"@type":"Question","name":"How did Lazarus Group's Operation Dream Job hide its C2 traffic to avoid network detection?","acceptedAnswer":{"@type":"Answer","text":"MISTPEN, the in-memory downloader used in Operation Dream Job, routes command-and-control traffic through Microsoft's Graph API and OneDrive, blending malicious communications with legitimate Microsoft traffic. Additionally, Lazarus compromised at least 17 third-party servers — including Roundcube webmail, WordPress, and PrestaShop sites — installing a PHP webshell called RelayShell to act as anonymous bidirectional relay nodes. Security engineers defending against nation-state C2 evasion techniques follow campaigns like Operation Dream Job on daily.dev."}},{"@type":"Question","name":"What is RelayShell and how was it used in the Lazarus Group Operation Dream Job campaign?","acceptedAnswer":{"@type":"Answer","text":"RelayShell is a PHP webshell deployed by Lazarus Group on compromised legitimate websites, including Roundcube webmail servers (via CVE-2025-49113), WordPress, and PrestaShop sites. Unlike a traditional command shell, it functions as a bidirectional relay node, turning compromised legitimate websites into anonymous middlemen for C2 traffic rather than exposing attacker-controlled infrastructure. Defenders investigating webshell-based relay infrastructure find threat breakdowns like this on daily.dev."}}]}
```

