Operation Dream Job: Fake Recruitment Lures, SecurityPDF, and the Troy Backdoor
A source-grounded investigation of Operation Dream Job, covering fake recruitment lures, the trojanized SecurityPDF viewer, the Troy backdoor, infrastructure relays, and practical checks for defenders.
Incident summary
Check Point Research reported on August 12, 2026 that a Lazarus-linked operation impersonated recruiters and targeted people connected to defense and aerospace organizations. The lure directed targets to run a trojanized PDF viewer called SecurityPDF, which led to deployment of the Troy backdoor.
Published attack chain
- An operator approaches a target with a plausible recruitment conversation and a job-related PDF.
- The target is prompted to run SecurityPDF, presented as a dedicated document viewer.
- SecurityPDF launches malicious components and the Troy backdoor, establishing persistent access.
- The chain uses CVE-2026-68820 in Windows AFD.sys to elevate privileges.
- Compromised Roundcube and CMS servers, together with a RelayShell PHP web shell, act as relay infrastructure.
Scope of the public evidence
The report documents tooling and portions of the infrastructure, but it does not enumerate every victim or every initial-access route. Defenders should therefore review any external recruitment interaction that resulted in installation of a viewer, VPN client, or remote-access utility rather than treating the campaign as limited to one industry.
Priority checks
- Unsigned software executed after recruiter or headhunter contact
- Executables launched from Downloads or temporary directories and unusual child processes
- Repeated connections to unrelated Roundcube or CMS servers and suspicious PHP paths
- Deployment status of the August 2026 Windows security updates
- New login locations, sessions, or mailbox forwarding rules on targeted accounts
Impact assessment
The cited public material does not describe a directly affected South Korean organization. However, organizations that receive international recruiting and collaboration requests may face the same social-engineering pattern. Security teams should isolate suspected endpoints, preserve volatile evidence, and examine identity and endpoint activity together.
Response priorities
- Deploy the August 2026 Windows security updates.
- Isolate systems that ran the suspicious software and preserve process, memory, and network evidence.
- Revoke active sessions and reset credentials and multi-factor authentication for affected users.
- Expand proxy, EDR, and mail-log searches across the organization for related senders, filenames, domains, and paths.
Information cutoff: August 15, 2026, 04:30 KST. Review the scope again when vendors publish additional analysis or indicators.
Sources reviewed
- Shattering the Dream: When a Job Offer Becomes a Zero-Day AttackCheck Point Research · Official source
- CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityMicrosoft Security Response Center · Official source
SECUFOCUS NOW reorganized and analyzed the material above. This article does not replace the original sources.