Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
Check Point Research documents a new wave of Operation Dream Job by DPRK-linked Lazarus group targeting the defense sector in Europe and India. The campaign uses two infection chains: DLL sideloading via a legitimate PDF viewer and a trojanized SecurityPDF viewer, both delivering MISTPEN downloader or Troy backdoor. The threat actor exploited CVE-2026-68820, a zero-day in Windows AFD.sys, to deploy FudModule v3.1 kernel rootkit for SYSTEM-level EDR disabling. C2 infrastructure relies on compromised Roundcube and WordPress servers running RelayShell, a novel PHP webshell acting as a communication relay.
- cveCVE-2025-49113PHP Object Deserialization vulnerability enabling remote code execution on Roundcube servers, exploited using leaked credentials to deploy RelayShell webshells for C2 relay infrastructure.
- cveCVE-2026-68820Use-after-free vulnerability in AFD.sys triggered by concurrent socket creation across multiple threads, allowing kernel read/write primitives and local privilege escalation to SYSTEM.
- domainenveil[.]onlineImpersonation website distributing trojanized SecurityPDF viewer, appeared as top search result for relevant queries
- domainenvell[.]xyzImpersonation website distributing trojanized SecurityPDF viewer, typosquat of Enveil company name
- domainuxtramine[.]orgImpersonation website distributing trojanized SecurityPDF viewer
- filenameE:\HK\Tool_Module\Troy_Handle\1Troy_Create_Dll_Tool\x64\Release\Test_Dll.pdbPDB path embedded in Troy backdoor sample, derived from the backdoor name
- filenamelibmupdf.dllMalicious sideloaded DLL loaded by legitimate PDF viewer executable, extracts and executes MISTPEN payload in memory
- filename%TEMP%\new.exeExecutable written by SecurityPDF after decrypting embedded payload from crafted PDF using single-byte XOR key 0x39
- ip135[.]181[.]185[.]158Troy backdoor C2 server and SecurityPDF distribution server
- ip135[.]181[.]67[.]203Troy backdoor C2 server and SecurityPDF distribution server
- sha25613d10bc99f7f7abe7ee0902be87920b73b2ea41bd9683dbfcad340dacbcdef79MISTPEN downloader sample
- sha2561de949c71efcfb0ffc41f33d38833dbc4b082075b1a540fc68c18c535d7ad86cDLL loader/dropper sample
- sha25621c3ad4838c4324bc5f081021da5fb2e9073d0c9304087811c21eb47c9e22762RelayShell PHP webshell sample
- sha256231b1ef8b95bf77887d5377e2a60f649035e78f543af1b82877db36a5759d858ForestTiger backdoor sample
- sha25629e24c007549e51319ff3aee011da6f9f93568e8c85a5ad69c9e53bd3f4533a2DLL loader/dropper sample
- sha2562b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca8DLL loader/dropper sample
- sha2562db25ac41a66aa523c79e23e00443573530dd7bd82b8371bcc87bd7232e141ebMISTPEN in-memory downloader using Microsoft Graph API and OneDrive for payload retrieval and C2
- sha2563601060c62edeeaa49def6a13be6e126e1024ce011faad4e2d9f585ccf6bd5a6Encrypted PDF payload sample
- sha256396192d92d17ace1a521f1351eeeba2825e60badd0d799cc5c338e4934b3c82cDLL loader/dropper sample
- sha2563a02d0d798e8d35555776886d92b20ff38a101c9ef7e0eebc8ce5d259516525aDLL loader/dropper sample
- sha2563b6378df8442e63a6ed7317075913e4720847a510d95022d4a8347b2637c245dFudModule v3.1 kernel-mode rootkit exploiting CVE-2026-68820 for SYSTEM privilege escalation and EDR disabling
- sha2564c9b804d6155b29f1e27a9ffe531e10bc42a7bdab42f905b50146bf2026768d9DLL loader/dropper sample
- sha2564dd792c9f672bbdcc8d363d745994efe90f4ffc5fdc2c059c8e379a48ad6a68aMISTPEN downloader sample
- sha2564ebdce2f47c23ff8c9e8e80c8b5239c7a5764da31cd3ab8f0505926890adc105DLL loader/dropper sample
- sha2564fd32432341dfcf54d0517a6bbc38e5d265be70933493e4183c2a340cdde9a2dMISTPEN downloader sample
- sha2565278ee922838352f1480a73e971161017d643a80b7ec22bf725897dfd088696dMISTPEN downloader sample
- sha256590fb6ae19480d694e08ee85859cad8066f2f87e7e5abba2960c6d115e1615d6Troy backdoor DLL, newly documented modular RAT with 17 C2 commands delivered via reflective loading
- sha25668d4fba7b1300a59cd6212c08910a260cd71b40cd9f51cac933030a68faac0bbTroy backdoor DLL sample
- sha2566da9b1e6f3315ceb77dd14a937a26cc3602bf6a7e2c2ecafb3c65ce5319837beForestTiger backdoor sample
- sha25672dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289ForestTiger backdoor sample
- sha256743172aab606974b054a64561534ae66baa3a840657f79d7c6fa18350e8d45d1SecurityPDF.exe trojanized PDF viewer that extracts and executes encrypted payloads from crafted PDF files
- sha25675b93a7103b0562f6497d30052c0c5cf7aa58c1bf0e9297022b74469a7f096f1DLL loader/dropper sample
- sha25682268052f94df6f4870d02e57b18d4c54136cc7a8c8d80ad162631f99462c943ForestTiger backdoor sample
- sha2568ce6c29f92dc45b1474417cbdff4ed0c18e58fa63e3a071ee9f85aa9d2aac07cEncrypted PDF payload sample
- sha25692106b0c62a0a42678232f8273f030b2d3c8e92efce81b98b9eec70cfe98afa1DLL loader/dropper sample
- sha256a0578a2b7821d7e2c573530648f26d7a0d98b373ab24fb7f0c792736761e542dForestTiger backdoor sample
- sha256a45144d22cac70a45d71cf4dffa4efbc373658779a56cf1300d6ac863d6cc7e2DLL loader/dropper sample
- sha256a673ae661593c0de9bbb815593b816a6853dad6d55ad5042d2ef1875cd13d6e7Encrypted PDF payload sample
- sha256a738059ce07c951c31ab2da3d93d8f69bff32f9b7d933dbf5943441b9cc99075Troy backdoor DLL sample
- sha256acb97cec84e08b89f41967a24e965d1fd2c51751cef158f7aa35bb4306b87b97Encrypted PDF payload sample
- sha256b4082d21070d9ddf53fde4ea22524d09e41ec9826ce63cef3c6235e458d21afbMISTPEN downloader sample
- sha256ba96c603e44046de703c67b2c3b7e4ca974afef7b437a0244418bc4edc781bb7MISTPEN downloader sample
- sha256c2aa28bb5e2a749c693712008276f311edd912f689371ef9e8a1ee5fb4167461DLL loader/dropper sample
- sha256cc4e06aa378a190f71384c03023bb3d18a6d66e297d46701220e132963d2e222RelayShell PHP webshell sample
- sha256d578c28c9afe7457a0d81f6701332ef8197e8f7468de654935fb29a50ea66459Encrypted PDF payload sample
- sha256db3d69b7eeda2e35e23006bf4b7e206281fce809584207214fc213f9bc30376dSecond SecurityPDF.exe trojanized PDF viewer sample
- sha256ea7056f2bf36c66a61ff787ff5be975a85f534c3c5ca178791dac2504db2c619MISTPEN downloader sample
- sha256f7e620134ca935067797ab957317b346ce0df84a4e9b9ca54a6acc9b75afda4dDLL loader/dropper sample
- sha256fb3fc5626f68677fb1269a2fefbe70e719211b4065e836ab92e06a8210139a2dMISTPEN downloader sample
- sha256fecf12088843801215898442bd1ff3e266f29d14e29a94780e857f69c4915d6bEncrypted PDF payload sample
Detection / Hunteropenrouter
What Happened
A North Korean hacking group called Lazarus has been targeting defense and aerospace companies with fake job offers. The attackers trick victims into downloading malicious software disguised as PDF readers or job description files. Once installed, the malware gives the attackers full control of the computer and can disable security software at the deepest level of the Windows operating system. The group also hacked into email servers belonging to other organizations and used them as hidden relay stations to manage their attacks, making it harder to trace the activity. Organizations in the defense sector, particularly in Europe and India, should verify that their Windows systems are patched with the August 2026 updates and educate employees about suspicious job offer communications.
Key Takeaways
- Lazarus group deployed FudModule v3.1 kernel rootkit exploiting CVE-2026-68820, a zero-day use-after-free in Windows AFD.sys driver affecting Windows 11 24H2/25H2, patched in August 2026
- Two distinct infection chains were active: a DLL sideloading chain using a legitimate PDF viewer with libmupdf.dll, and a trojanized SecurityPDF viewer that extracts and executes payloads from crafted PDF files
- New Troy backdoor provides 17 C2 commands including file exfiltration, process injection, and interactive shell capabilities, delivered as a 64-bit DLL via reflective loading
- Attackers compromised Roundcube webmail servers via CVE-2025-49113 to deploy RelayShell, a novel PHP webshell that turns compromised servers into C2 relay nodes using a file-based communication channel
- FudModule v3.1 introduces Smart App Control tampering by setting VerifiedAndReputablePolicyState to zero and triggering an in-place reload of code integrity policy via NtSetSystemInformation
Affected Systems
- Windows 11 build 26100 (24H2)
- Windows 11 build 26200 (25H2)
- Roundcube webmail servers (versions vulnerable to CVE-2025-49113)
- WordPress servers
- PrestaShop websites
Vulnerabilities (CVEs)
| CVE | Product | Severity | Description |
|---|---|---|---|
| CVE-2026-68820 | Microsoft Windows AFD.sys (Ancillary Function Driver) | High | Use-after-free vulnerability in AFD.sys triggered by concurrent socket creation across multiple threads, allowing kernel read/write primitives and local privilege escalation to SYSTEM. |
| CVE-2025-49113 | Roundcube webmail | Critical | PHP Object Deserialization vulnerability enabling remote code execution on Roundcube servers, exploited using leaked credentials to deploy RelayShell webshells for C2 relay infrastructure. |
Attack Chain
- Initial Access: Spear-phishing via fake job offers on professional networking platforms, directing victims to download encrypted ZIP archives or visit impersonation websites
- Execution: Victim runs legitimate PDF viewer with sideloaded libmupdf.dll or trojanized SecurityPDF.exe that extracts and executes embedded payload from crafted PDF
- C2 and Staging: MISTPEN downloader uses Microsoft Graph API to communicate via OneDrive, retrieving in-memory modules for reconnaissance, screenshots, and LPE exploitation
- Privilege Escalation: LPE module exploits CVE-2026-68820 in Windows AFD.sys driver to obtain SYSTEM privileges and execute FudModule v3.1 kernel rootkit
- Defense Evasion: FudModule disables EDR visibility by removing process/thread/image notify callbacks, minifilter callbacks, ETW providers, and tampering with Smart App Control policy
- Persistence and Exfiltration: ForestTiger or Troy backdoor deployed for long-term access, communicating through compromised Roundcube/WordPress servers running RelayShell webshell
Detection Availability
- YARA Rules: Yes
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Check Point Research blog post
A YARA rule for detecting RelayShell webshell is provided in the article IOC section. The rule targets string patterns and a hardcoded identifier found in the PHP webshell samples. No network detection rules or EDR queries are included.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Low | FudModule v3.1 is specifically designed to disable EDR visibility by removing kernel callbacks, minifilter callbacks, and ETW providers. Once executed with SYSTEM privileges, the rootkit can blind most endpoint detection tools. Prior to rootkit deployment, MISTPEN operates in-memory without touching disk, reducing file-based detection opportunities. |
| Network Visibility | Medium | MISTPEN uses Microsoft Graph API to communicate via OneDrive, blending with legitimate cloud service traffic. Troy and ForestTiger communicate over HTTP through compromised web servers, which may appear as normal web traffic. RelayShell uses HTTP POST requests to compromised servers acting as relay nodes, making C2 traffic difficult to distinguish from legitimate web browsing. |
| Detection Difficulty | Hard | The attack chain uses in-memory execution, legitimate cloud services for C2, DLL sideloading with signed executables, and a kernel rootkit that actively disables security telemetry. Multiple stages are designed to evade detection. The use of compromised legitimate web servers as relay nodes further complicates network-based detection. |
Required Log Sources
- Sysmon Event ID 1 (Process Creation)
- Sysmon Event ID 7 (Image Loaded - DLL sideloading detection)
- Sysmon Event ID 11 (File Creation)
- Sysmon Event ID 8 (Remote Thread Creation)
- Windows Event Log 4688 (Process Creation)
- ETW kernel telemetry (if not disabled by rootkit)
- Network connection logs (proxy, firewall, DNS)
- EDR process telemetry with command-line capture
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for PDF viewer processes loading unexpected DLLs from non-standard directories, which would indicate DLL sideloading activity | Sysmon Event ID 7 (Image Loaded) or EDR module load events filtering on PDF viewer process names | Execution | Medium - legitimate PDF viewers may load DLLs from various locations; focus on unsigned or recently created DLLs in user-writable paths |
| Consider hunting for processes making Microsoft Graph API calls that are not associated with known legitimate applications, which could indicate MISTPEN C2 activity | Network proxy logs, DNS logs, or EDR network connection events filtering on graph.microsoft.com destinations | Command and Control | Medium - many legitimate applications use Microsoft Graph API; correlate with unusual process ancestry or first-seen behavior |
| Consider hunting for child processes of msiexec.exe spawned by services.exe, which would indicate FudModule's two-hop process injection technique | Sysmon Event ID 1 (Process Creation) with parent process filtering | Privilege Escalation | Low - msiexec.exe spawned by services.exe is unusual in most environments |
| Consider hunting for processes writing executables to %TEMP% followed by immediate execution, which could indicate SecurityPDF payload extraction behavior | Sysmon Event ID 11 (File Creation) and Event ID 1 (Process Creation) correlated on %TEMP% path | Execution | Medium - legitimate installers and applications may write to %TEMP%; focus on PDF viewer process as parent |
| Consider hunting for NtSetSystemInformation calls with class 0xA4 and option 0x10000000, which would indicate FudModule Smart App Control tampering | EDR API call monitoring or kernel ETW telemetry if available before rootkit disables it | Defense Evasion | Low - this specific system information class and option combination is rarely used by legitimate software |
Control Gaps
- File-based AV scanning will miss MISTPEN and Troy which execute reflectively in memory without writing to disk
- Network-based detection may miss C2 traffic to Microsoft Graph API as it blends with legitimate cloud service usage
- EDR telemetry can be fully blinded once FudModule v3.1 executes and removes kernel callbacks and ETW providers
- DNS-based detection may miss C2 traffic to compromised legitimate web servers with good reputation scores
- Application allowlisting may be bypassed by Smart App Control tampering functionality in FudModule v3.1
Key Behavioral Indicators
- PDF viewer process (SmartaPDF.exe or SecurityPDF.exe) loading libmupdf.dll from same directory
- msiexec.exe spawned as child of services.exe with SYSTEM privileges
- Process writing new.exe to %TEMP% and immediately launching it as child process
- PDF viewer process making network connections to Microsoft Graph API endpoints
- NtSetSystemInformation calls with class 0xA4 from msiexec.exe context
- Processes named new.exe with PDF viewer as parent process
- HTTP POST requests to compromised web servers with Base64-encoded session identifiers in filenames
False Positive Assessment
Low - The IOCs are specific to this campaign including unique malware hashes, attacker-controlled domains impersonating a specific company, and novel malware families. The YARA rule for RelayShell targets specific obfuscated strings unlikely to appear in legitimate PHP files. However, behavioral detections based on Microsoft Graph API usage or PDF viewer process activity may generate false positives in environments with heavy legitimate use of these services.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider applying the August 2026 Windows Patch Tuesday updates to remediate CVE-2026-68820 on all Windows 11 24H2 and 25H2 systems.
- Consider blocking the identified C2 IP addresses (135.181.67.203, 135.181.185.158) and domains (envell.xyz, enveil.online, uxtramine.org) at network perimeter controls if consistent with your blocking policies.
- If your EDR supports hash-based blocking, consider adding the identified SecurityPDF.exe, Troy, FudModule, and MISTPEN SHA256 hashes to blocklists.
- Consider searching endpoint telemetry for the identified file hashes across your environment to detect potential prior compromise.
- If applicable, consider hunting for the marker string 'This document is encrypted with sumatrapdf reader!!!!!!!!!!!!' in files on disk or in network traffic captures.
Infrastructure Hardening
- Evaluate whether your organization runs Roundcube webmail servers and apply patches for CVE-2025-49113 if applicable.
- Consider auditing externally-facing WordPress and PrestaShop installations for compromise, particularly looking for unexpected PHP files that could be RelayShell webshells.
- If your network architecture supports it, consider implementing egress filtering to restrict direct connections to non-business IP addresses from server infrastructure.
- Consider deploying the YARA rule for RelayShell detection on web servers if file integrity monitoring or web shell scanning is supported by your tooling.
- Evaluate whether Microsoft Graph API traffic from non-standard processes can be monitored or restricted in your environment.
User Protection
- Consider deploying the August 2026 Windows security updates to all endpoints as a priority, particularly for systems running Windows 11 24H2 or 25H2.
- If your EDR supports it, consider enabling detection rules for DLL sideloading scenarios involving PDF viewer applications.
- Consider implementing application allowlisting for PDF viewer software to prevent execution of trojanized variants like SecurityPDF.exe.
- Evaluate whether Smart App Control is enabled on Windows 11 endpoints and monitor for policy tampering events.
Security Awareness
- Consider incorporating information about fake job offer phishing campaigns into existing security awareness training, particularly for employees in defense, aerospace, and aviation sectors.
- Advise employees to verify recruiter communications through official company channels before downloading files or visiting websites linked in messages.
- Consider reminding employees that legitimate companies do not require users to download custom PDF viewers from third-party websites to view job descriptions.
- If your organization uses professional networking platforms, consider guidance on verifying recruiter profiles and reporting suspicious job offer communications.
MITRE ATT&CK Mapping
Initial Access
Execution
Persistence
Privilege Escalation
Stealth
Discovery
Collection
Command and Control
Additional IOCs
- File Hashes:
db3d69b7eeda2e35e23006bf4b7e206281fce809584207214fc213f9bc30376d(SHA256) - Second SecurityPDF.exe trojanized PDF viewer sample68d4fba7b1300a59cd6212c08910a260cd71b40cd9f51cac933030a68faac0bb(SHA256) - Troy backdoor DLL samplea738059ce07c951c31ab2da3d93d8f69bff32f9b7d933dbf5943441b9cc99075(SHA256) - Troy backdoor DLL sample72dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289(SHA256) - ForestTiger backdoor sample231b1ef8b95bf77887d5377e2a60f649035e78f543af1b82877db36a5759d858(SHA256) - ForestTiger backdoor sample6da9b1e6f3315ceb77dd14a937a26cc3602bf6a7e2c2ecafb3c65ce5319837be(SHA256) - ForestTiger backdoor samplea0578a2b7821d7e2c573530648f26d7a0d98b373ab24fb7f0c792736761e542d(SHA256) - ForestTiger backdoor sample82268052f94df6f4870d02e57b18d4c54136cc7a8c8d80ad162631f99462c943(SHA256) - ForestTiger backdoor sample5278ee922838352f1480a73e971161017d643a80b7ec22bf725897dfd088696d(SHA256) - MISTPEN downloader sampleb4082d21070d9ddf53fde4ea22524d09e41ec9826ce63cef3c6235e458d21afb(SHA256) - MISTPEN downloader samplefb3fc5626f68677fb1269a2fefbe70e719211b4065e836ab92e06a8210139a2d(SHA256) - MISTPEN downloader sampleea7056f2bf36c66a61ff787ff5be975a85f534c3c5ca178791dac2504db2c619(SHA256) - MISTPEN downloader sample13d10bc99f7f7abe7ee0902be87920b73b2ea41bd9683dbfcad340dacbcdef79(SHA256) - MISTPEN downloader sample4fd32432341dfcf54d0517a6bbc38e5d265be70933493e4183c2a340cdde9a2d(SHA256) - MISTPEN downloader sample4dd792c9f672bbdcc8d363d745994efe90f4ffc5fdc2c059c8e379a48ad6a68a(SHA256) - MISTPEN downloader sampleba96c603e44046de703c67b2c3b7e4ca974afef7b437a0244418bc4edc781bb7(SHA256) - MISTPEN downloader sample2b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca8(SHA256) - DLL loader/dropper sample3a02d0d798e8d35555776886d92b20ff38a101c9ef7e0eebc8ce5d259516525a(SHA256) - DLL loader/dropper sample92106b0c62a0a42678232f8273f030b2d3c8e92efce81b98b9eec70cfe98afa1(SHA256) - DLL loader/dropper sample396192d92d17ace1a521f1351eeeba2825e60badd0d799cc5c338e4934b3c82c(SHA256) - DLL loader/dropper samplef7e620134ca935067797ab957317b346ce0df84a4e9b9ca54a6acc9b75afda4d(SHA256) - DLL loader/dropper sample75b93a7103b0562f6497d30052c0c5cf7aa58c1bf0e9297022b74469a7f096f1(SHA256) - DLL loader/dropper samplea45144d22cac70a45d71cf4dffa4efbc373658779a56cf1300d6ac863d6cc7e2(SHA256) - DLL loader/dropper sample1de949c71efcfb0ffc41f33d38833dbc4b082075b1a540fc68c18c535d7ad86c(SHA256) - DLL loader/dropper sample4c9b804d6155b29f1e27a9ffe531e10bc42a7bdab42f905b50146bf2026768d9(SHA256) - DLL loader/dropper sample29e24c007549e51319ff3aee011da6f9f93568e8c85a5ad69c9e53bd3f4533a2(SHA256) - DLL loader/dropper sample4ebdce2f47c23ff8c9e8e80c8b5239c7a5764da31cd3ab8f0505926890adc105(SHA256) - DLL loader/dropper samplec2aa28bb5e2a749c693712008276f311edd912f689371ef9e8a1ee5fb4167461(SHA256) - DLL loader/dropper samplea673ae661593c0de9bbb815593b816a6853dad6d55ad5042d2ef1875cd13d6e7(SHA256) - Encrypted PDF payload sample8ce6c29f92dc45b1474417cbdff4ed0c18e58fa63e3a071ee9f85aa9d2aac07c(SHA256) - Encrypted PDF payload sampleacb97cec84e08b89f41967a24e965d1fd2c51751cef158f7aa35bb4306b87b97(SHA256) - Encrypted PDF payload sample3601060c62edeeaa49def6a13be6e126e1024ce011faad4e2d9f585ccf6bd5a6(SHA256) - Encrypted PDF payload samplefecf12088843801215898442bd1ff3e266f29d14e29a94780e857f69c4915d6b(SHA256) - Encrypted PDF payload sampled578c28c9afe7457a0d81f6701332ef8197e8f7468de654935fb29a50ea66459(SHA256) - Encrypted PDF payload sample21c3ad4838c4324bc5f081021da5fb2e9073d0c9304087811c21eb47c9e22762(SHA256) - RelayShell PHP webshell samplecc4e06aa378a190f71384c03023bb3d18a6d66e297d46701220e132963d2e222(SHA256) - RelayShell PHP webshell sample
- File Paths:
%TEMP%\new.exe- Executable written by SecurityPDF after decrypting embedded payload from crafted PDF using single-byte XOR key 0x39E:\HK\Tool_Module\Troy_Handle\1Troy_Create_Dll_Tool\x64\Release\Test_Dll.pdb- PDB path embedded in Troy backdoor sample, derived from the backdoor name
- Command Lines:
- Purpose: Archive and exfiltrate files via Troy ZIPDOWNLOAD command | Tools:
powershell.exe| Stage: Exfiltration |powershell Compress-Archive -Path <source> -DestinationPath <temp_archive> - Purpose: Interactive command execution via Troy CMD command with working directory persistence | Tools:
cmd.exe| Stage: Execution |cmd.exe /c <command> - Purpose: Silent file and folder deletion via Troy DELETE command | Tools:
cmd.exe| Stage: Defense Evasion |cmd.exe /c del /q <path>
- Purpose: Archive and exfiltrate files via Troy ZIPDOWNLOAD command | Tools:
- Other:
Afd4Eop12_x64.dll- LPE exploit module DLL targeting CVE-2026-68820 in Windows AFD.sys, compiler timestamp July 7 2026Release_GetInfoPlugin_x64.dll- MISTPEN host reconnaissance module collecting domain, computer name, username, and OS versionRelease_PvPlugin_x64.dll- MISTPEN process listing module collecting PID, PPID, creation timestamp, and process namesOneScreenCapture64.dll- MISTPEN screenshot module capturing desktop via GDI APIs and returning Base64-encoded JPEGThis document is encrypted with sumatrapdf reader!!!!!!!!!!!!- Marker string checked by SecurityPDF in crafted PDF files to trigger payload extraction