The North Korea-linked Lazarus Group exploited a previously unpatched Microsoft Windows vulnerability to deliver a new backdoor against defense and aerospace companies in France, Germany, Brazil, and India. Check Point Research attributed the activity to Operation Dream Job, a long-running cyberespionage and social-engineering campaign. The attackers pose as recruiters on LinkedIn and other platforms, approaching professionals with fabricated job offers purportedly from companies including Lockheed Martin and Enveil. Victims are persuaded to open a malicious PDF or install a trojanized PDF viewer. Lazarus has used this tactic since at least 2022. The compromised viewer installs a new backdoor called Troy, giving the attackers remote access to the infected computer. The attackers exploited CVE-2026-68820, a privilege-escalation flaw in the Windows Ancillary Function Driver for WinSock, or AFD.sys. Microsoft patched the vulnerability, which has a CVSS score of 7.0, in its August 2026 Patch Tuesday updates. After gaining SYSTEM privileges, the attackers deploy FudModule 3.1, an updated version of a kernel-mode rootkit previously used by Lazarus. It can tamper with Windows Smart App Control, a feature that checks whether programs are safe to run, helping malicious tools evade security software. The group also used compromised WordPress and SharePoint websites and vulnerable Roundcube webmail servers instead of relying solely on dedicated infrastructure. Many of the Roundcube servers were vulnerable to CVE-2025-49113 and were infected with RelayShell, a previously undocumented PHP web shell used to exchange commands and responses. For system administrators in Somalia, the campaign offers a practical warning: install Windows updates promptly and obtain software through official channels, because both trusted-looking websites and convincing recruiter identities can be counterfeited.