Troy is a newly documented Lazarus Group backdoor used in Operation Dream Job espionage activity. It is delivered as a Windows DLL implant and is loaded directly into memory through a trojanized PDF-viewing workflow. In observed intrusions, victims were lured with fraudulent recruiter outreach and fake job opportunities, then induced to open specially prepared PDF documents or install a trojanized PDF viewer branded as SecurityPDF. When the crafted document was opened, the viewer decrypted an embedded payload and reflectively loaded the Troy implant in memory, reducing on-disk artifacts.
Troy provides remote access and supports 17 operator commands. Reported capabilities include interactive shell access, remote command execution, process termination, in-memory DLL injection, configuration updates, and file operations such as enumeration, upload, download, archiving, and exfiltration. The implant has been described as modular and suited to post-compromise espionage operations.
The malware has been associated with Lazarus campaigns targeting defense, aerospace, and aviation organizations, including victims in Europe, India, and South America. Troy appeared alongside other Lazarus tooling used in the same broader campaign, including MISTPEN, ForestTiger, and FudModule, though Troy itself is specifically the backdoor component delivered via the trojanized PDF viewer chain. Its use reflects Lazarus’s continued emphasis on recruiter-themed social engineering, in-memory execution, and stealthy remote access against high-value enterprise targets on Windows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attacks have been discovered to take use of CVE-2026-68820 (CVSS score: 7.0), a privilege escalation vulnerability that affects the Windows Ancillary Function Driver for WinSock ("AFD.sys"), which Microsoft fixed as part of their August 2026 Patch Tuesday upgrades. | ...the app decodes an embedded payload that loads a backdoor called Troy straight into memory.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...the app decodes an embedded payload that loads a backdoor called Troy straight into memory.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The group built at least three websites impersonating privacy technology vendor Enveil, some ranking top in search results... Those sites distributed a trojanized PDF viewer that runs a payload hidden inside crafted documents, delivering Troy, a previously undocumented backdoor supporting 17 operator commands.
targets are trapped via fake recruiter messages and lured into opening an infected PDF
Troy est un implant DLL unique... supportant 17 commandes opérateur : Accès shell interactif
Troy supports 17 different commands including interactive shell access, process termination, in-memory DLL injection and the ability to enumerate, upload, download, and archive and exfiltrate files.
распространяли модифицированный PDF-ридер SecurityPDF, который предназначался для выполнения малвари, встроенной в заранее подготовленные хакерами PDF-файлы.
archive chiffrée contenant un viewer PDF légitime signé numériquement, une DLL malveillante et un payload chiffré... le payload est déchiffré
Les attaquants usurpent l’identité de recruteurs... proposant de fausses offres d’emploi auprès d’entreprises reconnues... viewer PDF légitime signé numériquement... sites usurpant l’identité d’Enveil.
Check Point's analysis revealed that the hackers have also deployed a new backdoor called Troy that supports 17 commands, including the following: System and process reconnaissance
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly described backdoor used by Lazarus to provide remote access to infected systems and help attackers take control of compromised computers while evading security mechanisms.
A novel Lazarus backdoor loaded directly in memory by a trojanized PDF viewer. It supports interactive shell access, process termination, in-memory DLL injection, and file enumeration, upload, download, archiving, and exfiltration.
A newly referenced Lazarus backdoor launched when victims open the malicious PDF files delivered in the campaign.
Backdoor used as part of the Lazarus intrusion chain, delivered via trojanized PDF-viewer/job-offer lures and supported by cloud-backed C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.