CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4266

As cited

Citation snapshot as of .

vulnerabilities

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

Check Point Research documented Operation Dream Job, a Lazarus-affiliated campaign targeting defense and aerospace sectors globally through fake job offers and trojanized PDF viewers. The campaign deployed new malware including the Troy backdoor and exploited CVE-2026-68820, a zero-day in Windows AFD.sys driver, to escalate privileges using an updated FudModule rootkit; Microsoft patched the vulnerability on August 11, 2026. The threat actors compromised Roundcube webmail and other web servers to establish command-and-control infrastructure, leveraging a previously undocumented PHP webshell called RelayShell to relay traffic and maintain persistence.

Why it matters: Defense sector organizations in Europe, India, and other regions face active exploitation via spear-phishing and SEO-optimized fake vendor websites; patching CVE-2026-68820 immediately is critical, and Roundcube administrators should audit for CVE-2025-49113 exploitation and unauthorized RelayShell webshells.

Source published
First seen by Cybersecurity Tracker

Source attribution