Fake Job Offers Spread Lazarus Zero-Day Attack

Check Point Research · High sophistication
Last updated August 11, 2026

Researchers describe a real, ongoing Lazarus-linked campaign where targets are lured with attractive job offers and tricked into downloading a PDF viewer and “job description” documents. Opening the files installs backdoors and, in at least one wave, attackers used a Windows zero-day to gain deep control and reduce security visibility. The campaign heavily targets defense, aerospace, and aviation organizations, especially in Europe and India.

Key findings

  • Operation Dream Job uses job-offer lures to trick targets into downloading and opening files that install malware.
  • Attackers used encrypted ZIP archives containing a legitimate PDF viewer plus a malicious DLL and payload disguised as a PDF.
  • A newer infection chain uses a trojanized PDF viewer (“SecurityPDF”) plus a crafted PDF that triggers payload extraction and execution.
  • The campaign included impersonation websites and SEO to make downloads look legitimate (notably impersonating Enveil).
  • Lazarus exploited a Windows zero-day (CVE-2026-68820) to gain SYSTEM privileges and deploy the FudModule kernel rootkit.
  • Attackers also exploited vulnerable Roundcube webmail servers (CVE-2025-49113) and used RelayShell webshells as relay infrastructure.
  • In at least one case, a compromised Western European organization was used as a trusted launch point for further spear-phishing.

Who’s being targeted

  • Commonly targeted roles: Engineering, Aerospace/Aviation staff, Defense program teams, HR/Recruiting, Executive leadership.
  • Affected industries: Defense, Aerospace, Aviation.
  • Attack channels: email, website.
  • Impersonated: Recruiter for a well-known defense/aerospace company, Enveil (impersonated as the hiring company/vendor).

Awareness takeaways

  • Treat unsolicited job opportunities (especially in defense/aerospace) as high-risk and verify the recruiter and company through independent channels before opening files.
  • Never run a ‘viewer’ or other executable received via a job application message just to read a document; use approved tools and security review processes.
  • Be suspicious of vendor downloads reached via search results; attackers can use SEO and lookalike sites to make malicious installers seem legitimate.
  • Assume attackers may split delivery into steps (document first, ‘tool’ later) to evade defenses; report any multi-step download instructions to security.

Red flags to watch for

  • Encrypted ZIP archive sent unexpectedly
  • Instructions to run a viewer executable to read a PDF
  • Decoy “job description” content used to distract while malware runs
  • Download link points to a lookalike ‘vendor’ website found via search results
  • Viewer behaves unusually (e.g., asks to use a specific app to open a simple PDF)
  • Hidden execution triggered by opening a document
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email from a recruiter: “Job opportunity at a well-known defense company, see attached job description.” Sounds legit, right? This is Operation Dream Job. The ZIP hides a “PDF viewer” EXE, a fake PDF, and a malicious DLL. You run the viewer, a decoy job description opens, and in the background malware installs using a Windows zero-day. In another wave, they impersonate Enveil, push a trojanized “SecurityPDF” from a lookalike website, and any PDF with a hidden marker triggers payload execution every time you open it. Here’s the move: if a job email or vendor says “download our special viewer” to open a PDF, stop. Don’t run it, forward the message to security and ask them to check it.

Similar attacks

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools,…

August 13, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026
Lazarus “Dream Job” Lures Spread Zero-Day Attack

Lazarus “Dream Job” Lures Spread Zero-Day Attack

Check Point and Microsoft report North Korea’s Lazarus Group used a long-running “Dream Job” social engineering campaign to target defense-sector job seekers with fake employer sites and trojanized documents/software. Victims were lured into opening malicious PDFs or installing a modified PDF…

August 11, 2026
Fake Recruiters Target Job Seekers With Malicious PDFs

Fake Recruiters Target Job Seekers With Malicious PDFs

North Korea-linked Lazarus Group ran a “Dream Job” campaign targeting people applying for defense and aerospace jobs by posing as recruiters on LinkedIn and other platforms. Victims were sent malicious PDF files; opening them enabled a backdoor and then an exploit for a Windows zero-day…

August 12, 2026
Lazarus Job Offers Led to Windows Zero-Day

Lazarus Job Offers Led to Windows Zero-Day

North Korea’s Lazarus group targeted defense and aerospace staff using fraudulent job offers and fake websites, then deployed malware that pulled down and ran a Windows zero-day exploit. The campaign also used websites impersonating Enveil to distribute a trojanized PDF viewer that delivered a new…

August 12, 2026