Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India
Campaign
Updated: 12.08.2026 16:35
· First: 12.08.2026 16:35
· 📰 2 src / 2 articles
· H score: 22
Lazarus expanded Operation Dream Job into a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India, with successful targeting also observed in France, Germany, and Brazil. The activity used fraudulent recruitment offers and abused compromised Roundcube instances to hide communications, while Check Point tied the latest wave to Troy, RelayShell, and a FudModule variant that incorporated CVE-2026-68820. Microsoft patched CVE-2026-68820 in this month's Patch Tuesday and marked it actively exploited. Check Point also reported that the exploit supported Windows 11 builds 26100 and 26200 and that at least 17 servers were infected with RelayShell.