Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
2026-08-11T20:52:18Z•a66f1426b9b32edaae37068a6137cec2b0a091eebbd00ca0dc4cd934bbb9bda1
Cavern ManticoreCloudflare Code ModeCloudflare WorkersIran-linked APTLLM-enabled malwareMOISOilRigOperation Dream Jobaerospaceaviationbrowser-only ransomwarecommand and controlcrypto clipboard hijackerdata breachdefense sectormalicious PDFmemory corruptionmodified PDF viewerransomwaresandbox escapespearphishingsupply chain attackworkerdzero-day
What happened
Check Point Research reports a 2026 Operation Dream Job campaign targeting defense, aerospace, and aviation organizations worldwide. Threat actors distribute modified PDF viewers that execute malicious payloads embedded in specially crafted documents, reportedly leveraging a zero-day vulnerability. The feed also highlights five memory-corruption vulnerabilities in Cloudflare workerd affecting Code Mode and Workers, an Iran-linked Cavern Manticore modular C2 framework, browser-only ransomware techniques, and crypto clipboard hijacking. Specific CVE identifiers are not provided in the source.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- checkpoint_research
- Record identifier
- a66f1426b9b32edaae37068a6137cec2b0a091eebbd00ca0dc4cd934bbb9bda1
- Enrichment time
- 2026-08-11T20:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.