Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

2026-08-11T20:52:18Za66f1426b9b32edaae37068a6137cec2b0a091eebbd00ca0dc4cd934bbb9bda1
Cavern ManticoreCloudflare Code ModeCloudflare WorkersIran-linked APTLLM-enabled malwareMOISOilRigOperation Dream Jobaerospaceaviationbrowser-only ransomwarecommand and controlcrypto clipboard hijackerdata breachdefense sectormalicious PDFmemory corruptionmodified PDF viewerransomwaresandbox escapespearphishingsupply chain attackworkerdzero-day

What happened

Check Point Research reports a 2026 Operation Dream Job campaign targeting defense, aerospace, and aviation organizations worldwide. Threat actors distribute modified PDF viewers that execute malicious payloads embedded in specially crafted documents, reportedly leveraging a zero-day vulnerability. The feed also highlights five memory-corruption vulnerabilities in Cloudflare workerd affecting Code Mode and Workers, an Iran-linked Cavern Manticore modular C2 framework, browser-only ransomware techniques, and crypto clipboard hijacking. Specific CVE identifiers are not provided in the source.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
checkpoint_research
Record identifier
a66f1426b9b32edaae37068a6137cec2b0a091eebbd00ca0dc4cd934bbb9bda1
Enrichment time
2026-08-11T20:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.