The lure looked professional
A recruiter and a familiar employer name opened the conversation.
Check PointThe page’s question: what does “trusted” mean when every link can be authentic and still be used by someone else?
In the new Operation Dream Job wave, a familiar name, signed software, a Microsoft service and a compromised organisation could all belong to the same malicious story. The lesson is relational: an authentic thing does not authenticate the chain that carries it.
Choose a link. Read what was real and what was abused.
“Real” describes a thing. “Safe” describes its relationship with the rest of the chain.Evidence that holds the chain in place
Microsoft and CISA support the vulnerability status.
The attribution belongs to Check Point’s analysis.
The organisation is not named publicly.
The research does not list exfiltrated information.
The new signal
Fake job offers from the Lazarus ecosystem are familiar. The new feature in this reconstruction is the combination: recruitment, genuine software, search visibility, OneDrive, a kernel zero-day, compromised web servers and a victim used for the next round.
For a defender, that changes the question. A familiar domain, a valid signature or a mainstream cloud service describe an object. They do not automatically verify the relationship between that object and the message that brings it into a network.
“Real” describes a thing. “Safe” describes its relationship with the rest of the chain.
01 · What happened
Before reading the signals, here is the four-moment operational reconstruction. It follows the primary source’s described sequence; it is not a complete list of victims or impact.
A recruiter and a familiar employer name opened the conversation.
Check PointA signed PDF viewer and OneDrive made the installation and traffic look ordinary.
Check PointCVE-2026-68820 in Windows AFD.sys opened the route to SYSTEM.
CISACompromised web servers and the reputation of an organisation in France were reused for traffic and later messages.
Check Point02 · The signals
Each row carries a signal that a reader or a system might recognise. Open it to see the signal’s limit.
The name was familiar. The published research does not indicate company involvement in the campaign. Open source: Check Point Research
Professional identity is easy to borrow when a target expects a job offer or a technical conversation. Open source: Check Point Research
An authentic signature attests to a file’s origin, not to the intent of the person placing it in the chain. Open source: Check Point Research
Search visibility supplied a second legitimacy signal. Open source: Check Point Research
A real service can carry traffic with a malicious purpose. Open source: Check Point Research
Microsoft patched the vulnerability on 11 August 2026. CISA listed it as actively exploited. Open source: CISA · Known Exploited Vulnerabilities
The organisation is not named publicly. Its reputation became an operational asset for later messages. Open source: Check Point Research
Check Point identified at least 17 identifiers corresponding to likely compromised servers. Open source: Check Point Research
The investigation describes Troy, FudModule v3.1 and RelayShell as parts of the attack architecture. Open source: Check Point Research
genuine in itself, while still usable in a malicious relationship
an identity, page or context imitates a familiar signal
a legitimate resource was taken over and used by someone else
the component or action belongs to the attack chain
03 · Escalation
The technical path becomes legible when the social opening remains in the same timeline as the system-level outcome.
CVE-2026-68820 is confirmed as actively exploited. The link to Lazarus for this wave remains Check Point’s assessment.
Researchers send the vulnerability to Microsoft.
The issue enters the coordinated patch process.
The vulnerability becomes CVE-2026-68820.
Microsoft publishes the fix and CISA adds it to Known Exploited Vulnerabilities.
The Record separates confirmed exploitation from Check Point’s attribution.
04 · Victim as infrastructure
Check Point describes two forms of reuse. Legitimate web servers carried implant communications, while an organisation headquartered in France was later used for spear-phishing. Choose the route you want to follow.
Traffic passes through a compromised legitimate server and resembles ordinary HTTPS.
compromised in France
Roundcube / CMS + RelayShell
pass through ordinary infrastructure
the victim’s name raises message credibility
spear-phishing toward later targets worldwide
05 · What we know
The page keeps separate what the sources document, the actor assessment, the inference about technical continuity and what the research does not publish.
Microsoft patched CVE-2026-68820, and CISA listed it in the KEV catalogue as actively exploited.
Open source: CISA · Known Exploited VulnerabilitiesCheck Point attributes this wave to the Lazarus / DPRK ecosystem. Public Microsoft and CISA materials confirm the vulnerability and exploitation without making that attribution themselves.
Open source: Check Point ResearchThe fact that FudModule previously used a vulnerability in the same AFD.sys driver suggests sustained technical knowledge. That is an interpretation, not evidence of who discovered each bug.
Open source: Check Point ResearchThe research does not say what defence information was exfiltrated from each victim, who consumed it or whether the operation concretely changed a weapons programme.
Open source: Check Point ResearchThe Romanian question
The public material does not disclose a Romanian victim. The research question is still clear: Romanian suppliers of drones, surveillance sensors, robotics and aerospace technology sit in the same technology categories named in the campaign analysis. This is an inference about exposure, not a report of a compromise.
The target categories come from Check Point’s analysis ↗What travels beyond the page
When a message looks legitimate, three questions are useful:
In this campaign, the answer to the third question was the infrastructure of the next target.
Sources and limits
Check Point provides the main technical reconstruction. CISA and Microsoft support the public vulnerability record. The Record helps separate confirmed exploitation from the actor attribution.
The campaign, malware, relay servers and French victim reuse reconstruction.
CVE-2026-68820 listed as actively exploited.
The vulnerability record and Microsoft patch context.
Patch and exploitation separated from Check Point’s DPRK attribution.
Current as of 13 August 2026. Re-review if primary sources change the description of exploitation, the CVE-2026-68820 status, the attribution or the limits around victim impact.