logo

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

ID: f5937899-cf68-595e-86e1-ef6d0d8a6e13

STIX ID: report--f5937899-cf68-595e-86e1-ef6d0d8a6e13

Feed Name: Check Point Research

Threat Score
90/100

Date Published: 2026-08-11

Date Updated: 2026-08-11

Author: matthewsu

...
...

**Executive Summary:** Check Point Research documents an active Operation Dream Job campaign attributed to the Lazarus APT that targeted defense and aerospace organizations worldwide using spear-phishing, trojanized PDF viewers, and SEO-driven impersonation sites to deliver modular in-memory malware (MISTPEN), a newly observed Troy backdoor, and a kernel-mode rootkit (FudModule) leveraging a zero-day AFD.sys LPE (CVE-2026-68820); the report includes detailed technical analysis, IOCs, YARA, and a disclosure timeline culminating in a Microsoft patch on August 11, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.