Lazarus Operation Dream Job: PDF Launch Action Dropping the Troy Backdoor (afd.sys Zero-Day CVE-2026-68820)
On August 11, 2026, Microsoft's August Patch Tuesday fixed 421 CVEs, including CVE-2026-68820 (CVSS 7.0) — a use-after-free in afd.sys, the Ancillary Function Driver behind WinSock, that lets an attacker escalate to SYSTEM. It is the only flaw Microsoft flagged as under active exploitation, and Check Point Research attributes it to North Korea's Lazarus Group in its Operation Dream Job campaign; CISA added it to KEV the same day with a federal fix deadline of August 25. Dream Job distributes a trojanized PDF viewer (SecurityPDF) that drops the Troy backdoor, targeting defense, aerospace, and aviation organizations in Europe and India. Post-exploitation chains the afd.sys zero-day with the FudModule rootkit to gain SYSTEM and disable EDR, while relays run on compromised Roundcube servers (CVE-2025-49113) and WordPress hosts rigged with the RelayShell PHP webshell. This demo ships a PDF whose OpenAction Launch entry invokes an external program the moment the file is opened — the same abuse pattern a Dream Job lure would carry — with the payload reduced to opening the calculator (safe, nothing destructive). MetaDefender Deep CDR parses the PDF, strips the Launch/OpenAction entries and all active content, and rebuilds a clean, fully functional document that cannot execute anything.
Attack Technique
PDF OpenAction Launch executing an external program on open (User Execution: Malicious File)
MITRE ATT&CK
T1204.002 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗