The Lazarus Group is at it again. And Augur’s predictive threat intelligence engine flagged Lazarus Group infrastructure used in the current Operation Dream Job activity surge years in advance.
The DPRK-linked group is still running live campaigns against global aerospace and defense targets, weaponizing trojanized PDF lures to deliver the Troy backdoor and zero-day exploits (including a previously unknown Windows AFD.sys privilege escalation) before deploying an upgraded FudModule rootkit that blinds EDR agents and establishes kernel-level persistence (read the full analysis on the Check Point Blog).
Augur’s Predictive Threat Intelligence (PTI) identified 4 of 5 IOCs from the Check Point research and blocked them for customers well before the first victim opened a PDF.

Dream Job Attack Chain
Here is how the attack chain unfolds. The attack begins with fake recruitment lures sent via social media or email, directing victims to open a malicious document using a customized binary called SecurityPDF. Once executed, the malware exploits a local privilege escalation vulnerability in Windows Ancillary Function Driver (AFD.sys) (CVE-2026-68820) to bypass security boundaries. This allows the threat actors to deploy an upgraded version of the FudModule rootkit, which tampers with the kernel and blinds Endpoint Detection and Response (EDR) agents, securing persistent, undetected administrative access.
The campaign's command-and-control (C2) infrastructure leverages compromised legitimate web servers and multi-tiered communication chains to obfuscate malicious traffic. A significant portion of the network utilizes hacked Roundcube webmail instances and SEO-poisoned websites to blend in with normal traffic. Lazarus employs an intermediary tool known as RelayShell on these compromised nodes, transforming legitimate servers into traffic relays that forward commands between the victim's endpoint and the primary actor-controlled C2 servers. Routing data through these infected third-party networks lets threat actors successfully hide their true infrastructure and bypass standard IP-based perimeter defenses.
What Augur Saw
Augur's predictive threat intelligence (PTI) engine flagged malicious infrastructure associated with these Lazarus operations in advance. Telemetry confirmed coverage across four of the five indicators associated with this campaign, with initial detection predating the 2026 Check Point disclosure by several years. The IP 135.181.185[.]158 and the domain uxtramine[.]org were both identified by Augur on December 14, 2020, within the 135.181.185.144/28 CIDR block, hosted on Hetzner Online GmbH (AS24940). The IP 135.181.67[.]203 and domain envell[.]xyz were similarly identified through clustering on June 13, 2026, as part of the adjacent 135.181.67.200/29 block on the same autonomous system. The consistent selection of tight /28 and /29 CIDR blocks within Hetzner's German-registered AS24940 space reflects a deliberate pattern: Lazarus operators favor disposable VPS nodes within a low-cost, high-volume European hosting provider where individual IP reputation signals are difficult to analyze at scale.
The clustering of both historical and recent indicators within the same ASN across a six-year window is consistent with Lazarus Group's documented preference for Hetzner Online as a long-term infrastructure provider. Instead of typical threat actor rotation, Lazarus has repeatedly returned to the same autonomous system, relying on the density of legitimate traffic within AS24940 to absorb malicious nodes.
80% of IOCs Identified & Blocked Ahead of Attacks
Augur's CIDR-level blocking of 135.181.67.200/29 and 135.181.185.144/28 would have preemptively neutralized the 2026 infrastructure wave before any host-level compromise could be established, underscoring the value of predictive infrastructure coverage against threat actors with stable, identifiable hosting preferences.
Organizations operating within aerospace, defense, and technology sectors should treat Lazarus Group infrastructure as an active indicator of ongoing risk. Augur's CIDR-level coverage provides the earliest available signal against this actor and blocks access before the lures ever land.
For questions or additional analysis, contact: research@augursecurity.com



