Lazarus Group is exploiting a recently patched Windows zero-day, CVE-2026-68820, to deliver a new backdoor called Troy against defense and aerospace targets in France, Germany, Brazil, and India through Operation Dream Job. The campaign uses fake recruiter lures, trojanized PDF software, and compromised legitimate sites and servers to spread MISTPEN, ForestTiger, FudModule 3.1, and RelayShell while evading security controls. #LazarusGroup #OperationDreamJob #CVE-2026-68820 #Troy #MISTPEN #ForestTiger #FudModule31 #RelayShell #Enveil #AFDsys
Keypoints
- Lazarus Group abused a Windows zero-day to deploy the Troy backdoor.
- The attacks targeted defense and aerospace organizations in multiple countries.
- Operation Dream Job used fake recruiter messages and trojanized PDF tools.
- Two infection chains delivered MISTPEN, ForestTiger, and FudModule 3.1.
- The campaign also used compromised WordPress, SharePoint, and Roundcube systems for C2.
Read More: https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html