A sophisticated cyber-espionage campaign linked to North Korea’s Lazarus Group has placed India’s expanding defence and aerospace sector among its targets, using fraudulent recruitment opportunities, weaponised PDF files, compromised internet infrastructure and a previously unknown Windows vulnerability to penetrate selected systems.
The campaign is the latest phase of Operation Dream Job, a long-running cyber operation in which individuals working in strategically important industries are approached with apparently attractive employment opportunities. Check Point Research, which published its latest investigation on August 11, 2026, said the current wave has concentrated heavily on defence organisations and particularly on companies involved in aerospace, aviation, surveillance sensors, drones and robotics. India is specifically identified by the researchers as one of the notable countries targeted.
The significance for India is considerable. As the country expands indigenous production of aircraft, UAVs, missiles, sensors, electronic warfare systems and other advanced technologies, engineers and specialists working inside the defence-industrial ecosystem increasingly possess knowledge that can itself become a target of foreign cyber-espionage operations.
Operation Dream Job Returns With More Sophisticated Tools
Operation Dream Job is not a newly discovered campaign. Lazarus has used the recruitment theme for years, particularly against personnel working in defence, aerospace, technology and other high-value industries.
MITRE ATT&CK records Operation Dream Job as a cyber-espionage campaign likely conducted by Lazarus and documents previous targeting involving India as well as the United States, Israel, Australia and Russia. It also records the group’s established use of fictitious employment opportunities, LinkedIn personas and malicious job-related documents as mechanisms for approaching prospective victims.
The latest campaign, however, introduces a considerably more advanced technical arsenal.
Check Point said it has been tracking the new wave since early 2026. The attackers have distributed modified PDF viewers capable of executing hidden malware embedded within specially prepared files while also using impersonation websites and search-engine optimisation techniques to make malicious software appear legitimate.
Instead of relying solely on a conspicuous malicious attachment, the operation attempts to reproduce elements of an authentic recruitment process.
A Defence Job Description Becomes the Entry Point
One infection chain begins when the target is persuaded to download an encrypted archive containing a genuine digitally signed PDF viewer, a malicious DLL and what appears to be a PDF document.
When the legitimate application is opened, the accompanying malicious DLL is loaded through a technique known as DLL sideloading. The user is shown an ordinary-looking recruitment document while malicious software is simultaneously decrypted and executed in memory.
Check Point researchers discovered a decoy that impersonated a Lockheed Martin job description, illustrating how well-known defence companies can be used to give the approach credibility.
Behind the document, malware identified as MISTPEN begins operating. MISTPEN acts as an in-memory downloader and uses Microsoft’s Graph API and attacker-controlled OneDrive files to obtain additional components.
The malware can first collect information about the target computer and its running processes. Once the attackers determine that the machine is valuable, additional components can establish persistence and prepare the system for deeper compromise.
Lazarus Exploited a Previously Unknown Windows Vulnerability
The most important technical discovery in the campaign is the exploitation of CVE-2026-68820, a vulnerability affecting Microsoft’s AFD.sys, the Windows Ancillary Function Driver used in networking operations.
Check Point researchers determined that Lazarus was exploiting the flaw as a zero-day, meaning the attackers were using the vulnerability before a security fix was publicly available.
The exploit enables privilege escalation after an attacker has already gained access to a computer. By exploiting the vulnerability, Lazarus could obtain SYSTEM-level privileges, giving its malware extremely powerful access within Windows.
Check Point reported the vulnerability to the Microsoft Security Response Center on July 28, 2026. Microsoft confirmed the issue on July 31, assigned CVE-2026-68820 on August 5 and issued a fix as part of its August 11 Patch Tuesday security updates, according to the researchers’ coordinated-disclosure timeline.
This makes installation of the latest Microsoft security updates particularly important for organisations operating sensitive Windows systems.
FudModule Attempts to Blind Security Monitoring
After obtaining elevated privileges, the attackers deploy a new version of FudModule, a kernel-level rootkit previously associated with Lazarus operations.
A rootkit operating at this level can interfere with the mechanisms security software uses to observe what is happening inside a computer.
Check Point’s analysis found that the latest FudModule includes capabilities designed to interfere with security-product visibility and Windows telemetry. The rootkit can manipulate several monitoring mechanisms and help attacker-controlled components operate with SYSTEM privileges while reducing the visibility available to endpoint detection and response systems.
This is particularly relevant for defence organisations because sophisticated espionage campaigns are often designed not merely to gain temporary access but to remain inside networks long enough to identify valuable engineering, technical or operational information.
New SecurityPDF Attack Introduces the Troy Backdoor
Researchers discovered a second infection route in July 2026.
In this version, the attackers impersonated Enveil, a legitimate privacy-enhancing technology company. Check Point stressed that there was no indication that Enveil itself had been compromised.
Victims were directed towards a modified PDF program named SecurityPDF. The application is based on the legitimate open-source MuPDF framework but has been altered so that specially crafted PDF files can trigger the extraction and execution of malware.
Check Point identified at least three websites impersonating Enveil and distributing the trojanised viewer. Particularly concerning was the researchers’ observation that some of these sites appeared prominently in search results, giving potential victims another reason to believe that they were downloading legitimate software.
Once the specially prepared document is opened through SecurityPDF, it launches a previously undocumented Lazarus backdoor that researchers named Troy.
Troy Gives Attackers Extensive Control of the Computer
Troy is a modular remote-access trojan capable of supporting 17 separate commands.
Once established on a machine, it can enumerate drives and directories, start programs, delete files and folders, download files from the victim, upload additional files, execute command-line instructions and obtain information about running processes.
It can also inject DLL payloads directly into running processes and compress files for subsequent exfiltration.
The combination effectively gives a remote operator extensive control over a compromised workstation.
For an ordinary home computer, this would already represent a serious breach. On an engineering workstation belonging to someone involved in military aerospace, UAV development, sensors or robotics, the intelligence value could be substantially greater.
Lazarus Hides Behind Compromised Legitimate Websites
Another notable aspect of the operation is the way Lazarus attempts to conceal its command-and-control infrastructure.
Rather than depending entirely upon obviously attacker-owned servers, the group has been using compromised Roundcube webmail servers, WordPress installations and other websites as intermediaries between infected computers and the attackers.
Check Point discovered a new PHP web shell called RelayShell, which converts compromised servers into communications relay points. Researchers identified 17 unique identifiers, indicating that at least 17 compromised servers were probably being used as relay nodes during the investigated campaign.
Many of the Roundcube installations examined by Check Point were vulnerable to CVE-2025-49113. Researchers assess that attackers probably combined leaked legitimate credentials with exploitation of the vulnerability to install RelayShell on selected servers.
Using legitimate but compromised internet infrastructure gives the attackers an important advantage: communications from an infected computer can resemble traffic to ordinary websites rather than connections to an obvious malicious command server.
Even a Compromised Organisation Can Become a Weapon
The campaign demonstrates another dangerous progression in supply-chain-style cyber operations.
Check Point found that an organisation headquartered in France, after being compromised, was subsequently used to conduct spear-phishing attacks against additional targets around the world. The use of a real organisation can make a malicious message significantly more convincing because the communication originates from infrastructure that the recipient may recognise or trust.
This means organisations must increasingly evaluate the contents and context of communications rather than assuming that a familiar sender or legitimate domain automatically makes a file safe.
India Emerges as an Important Target
Check Point describes the latest campaign as global, with successful targeting observed in Western Europe and activity extending into South America. France, Germany and Brazil appear within the researchers’ investigation, while India is singled out as another notable target because of its substantial and rapidly expanding defence and aerospace industry.
India’s defence-industrial ecosystem has undergone a major transformation during the past decade. Indigenous programmes now extend across combat aircraft, helicopters, missiles, radars, electronic warfare, satellites, UAVs, counter-drone systems, naval platforms and advanced military electronics, while private companies and start-ups are assuming a growing role alongside established public-sector organisations.
This expansion also increases the number of engineers, scientists, software developers and specialist personnel who may hold commercially or strategically valuable information.
The attraction of such personnel to foreign intelligence-linked cyber actors is therefore understandable. The target is not necessarily only a company’s central network. An individual engineer’s laptop can potentially provide credentials, project documents or the initial access necessary for a much broader intrusion.
UAV Technology Has Already Attracted Lazarus Attention
The targeting fits a pattern previously identified by other cybersecurity researchers.
In October 2025, ESET documented another phase of Operation Dream Job directed at companies connected with unmanned aerial vehicle technology. Its investigation found Lazarus using fake employment approaches and malicious software against European organisations connected with defence and aerospace.
ESET also documented the Lazarus malware known as ScoringMathTea, also called ForestTiger, and recorded earlier activity involving an Indian technology company as well as defence, aerospace and industrial targets elsewhere.
ForestTiger again appears in Check Point’s latest investigation as one of the final backdoors delivered through one of the current Dream Job infection chains.
The continuity suggests that recruitment-themed cyber espionage is not an opportunistic experiment but a persistent method within Lazarus operations.
The Human Being Has Become Part of the Attack Surface
One of the most important lessons from Operation Dream Job is that highly protected defence networks can still be approached indirectly through people.
An engineer may legitimately receive messages from recruiters. Aerospace specialists frequently move between companies. Defence technology professionals attend international conferences, maintain LinkedIn profiles and communicate with suppliers, researchers and recruiters outside their organisations.
Lazarus attempts to turn that normal professional activity into an intelligence opportunity.
Check Point says the precise initial-contact mechanism in every incident from the current campaign was not directly observed. Based on previous Operation Dream Job activity, however, researchers assess that professional networking services such as LinkedIn or direct messaging applications are likely to have been used, with attackers posing as recruiters before directing targets towards malicious material.
That distinction is important because the confirmed element is the recruitment-themed infection infrastructure and malware chain, while the exact first message may vary between victims.
A Cybersecurity Warning for India’s Defence Ecosystem
For Indian defence and aerospace organisations, the latest Lazarus campaign reinforces the need to treat cyber defence as part of protection of intellectual property and strategic technology.
Employees involved in sensitive projects should independently verify unexpected recruitment approaches through official company channels before downloading documents or specialised viewers. Software obtained through links supplied by unknown recruiters deserves particular scrutiny, even when the accompanying website looks professional or appears prominently in search results.
Most importantly, Windows systems should receive Microsoft’s August 2026 security updates, because the vulnerability exploited in this campaign was being actively used before the patch was released. Organisations should also examine endpoint and network telemetry for the indicators and malware families published by Check Point Research.
The attack also demonstrates why cyber-security training cannot be restricted to obviously suspicious emails containing crude attachments. Modern state-linked campaigns can combine detailed reconnaissance, convincing professional identities, authentic-looking job descriptions, digitally signed legitimate programs, compromised websites, search-engine manipulation, zero-day vulnerabilities and highly specialised malware.
Cyber Espionage Follows Technological Capability
The targeting of India should ultimately be seen in the context of the country’s rapidly growing technological capabilities.
As Indian companies develop increasingly sophisticated military aircraft, UAVs, sensors, missiles, electronics, artificial intelligence systems and autonomous platforms, the technology and expertise inside these organisations become strategically valuable.
Operation Dream Job illustrates how the competition for such knowledge increasingly extends beyond laboratories, factories and conventional intelligence collection into cyberspace.
The latest Lazarus campaign therefore carries a clear message for India’s expanding defence-industrial base: protecting indigenous technology now also means protecting the engineers, scientists and digital systems that create it.
Authenticity assessment: High. The central claims concerning the 2026 campaign, Indian targeting, SecurityPDF, Troy, FudModule, CVE-2026-68820 and the August 11 patch are supported directly by Check Point Research’s investigation published on August 11, 2026. The established history and methodology of Operation Dream Job are independently documented by MITRE ATT&CK and ESET.
You may also like
-
TRAI Introduces 1601-Series Numbers for Utility, Courier and Logistics Service Calls
-
Green India Mission Restores Over 1.84 Lakh Hectares Across 18 States and UTs Since 2015
-
Beyond Agni-5: How India Could Turn Its Long-Range Missile Into an Entire Family of Strategic Weapons
-
HAL Revives Su-30MKI Production at Nashik, 12 New Fighters to Join IAF by 2029
-
Indian Navy’s Next Generation Offshore Patrol Vessel ‘Shruti’ Launched at GRSE Kolkata