What happened
Check Point found that North Korea's Lazarus Group had been exploiting CVE-2026-68820, a local privilege escalation flaw in the Windows AFD.sys driver, in its Operation Dream Job campaign since at least early July 2026. Microsoft patched the zero-day on 11 August 2026. Targets were defence and aerospace organisations, mainly in Western Europe and India and extending to South America. Successful compromises deployed the FudModule kernel rootkit and a backdoor named Troy.
How the deception worked
Operators posed as recruiters offering roles at legitimate companies, most plausibly approaching targets through LinkedIn or messaging apps, and steered them into downloading malicious files including a trojanised PDF. The pretext works because a defence engineer receiving a career approach has a legitimate reason to open an attached job description or assessment. Execution then escalated to SYSTEM through the AFD.sys zero-day, installing a kernel-mode rootkit. One compromised French organisation was reused as a launch point for spear-phishing further targets, borrowing its real domain and relationships as the next trust signal.
The control that would have caught it· our reading, not a claim from the sources
Recruitment documents from unsolicited approaches should be opened only in a sandbox or a browser-based viewer, and application allowlisting stops the downloaded binary before the privilege escalation matters.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.