Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Security Affairs · High sophistication
Last updated August 14, 2026

Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools, and relied heavily on hijacked legitimate websites and webmail servers to blend in. Confirmed targets were found in multiple countries including France, Germany, Brazil, and India.

How the attack worked

This campaign, known as Operation Dream Job, targeted defense and aerospace professionals with fake job offers, including one referencing Lockheed Martin. Two infection paths were used. In one, victims downloaded an encrypted archive containing a legitimate signed PDF viewer bundled with a malicious DLL that displayed a convincing job description while quietly compromising the machine. In the other, victims were told to download a trojanized viewer called SecurityPDF from websites impersonating Enveil, a legitimate privacy technology company with no actual connection to the attack. Once installed, that modified viewer inspected any PDF opened through it for a hidden marker.

The role of the zero-day and hijacked infrastructure

The attackers used a previously unknown Windows vulnerability, CVE-2026-68820, to gain full control of infected systems and reduce visibility for security tools. Rather than running their own infrastructure, they relayed commands through hijacked legitimate websites and webmail servers, including compromised Roundcube and WordPress installations. In at least one case, infrastructure belonging to a previously breached organization was reused to send phishing messages onward to new victims, making detection harder because the traffic looked like normal, trusted activity.

Why it succeeded

The pretext relied on something professionals in defense and aerospace fields are conditioned to respond to: recruiting outreach for relevant, high-value roles. Requiring a special viewer to read a job description added a layer of plausibility, since defense-related documents are sometimes handled with dedicated tools. Combined with a signed viewer in one chain and a convincing lookalike brand in the other, the technical and social elements reinforced each other.

What to watch for

  • Unsolicited recruiting messages that ask you to install or run a viewer just to read a job description
  • Archives that contain executables or DLLs rather than a simple document
  • Requests to download software from a website that is not the official company domain
  • Job-related links or attachments arriving via webmail or websites that seem slightly off

Building resistance

Organizations in defense, aerospace, and government contracting should train staff to verify recruiter and company identity through known official channels before opening any attachment or installing any tool. Standard PDFs should never require a special viewer, and any request to do so should be treated as a red flag. Because this campaign relied on a real Windows zero-day, prioritizing fast patching for critical updates, including the August 2026 Patch Tuesday fix for CVE-2026-68820, remains an important complementary defense alongside awareness training.

Key findings

  • Lazarus used fake job offers (including a Lockheed Martin job description) to trick targets into running malicious PDF-viewer software.
  • The campaign exploited a Windows zero-day (CVE-2026-68820) to gain elevated control and reduce EDR visibility; Microsoft shipped a fix in August 2026 Patch Tuesday.
  • Two infection chains were described: (1) encrypted archive with a legitimate signed PDF viewer plus a malicious DLL; (2) a trojanized “SecurityPDF” viewer downloaded from websites impersonating Enveil.
  • Attackers relied on hijacked infrastructure (compromised websites, Roundcube webmail, WordPress) to make command-and-control traffic look legitimate.
  • In at least one case, a previously breached French organization’s infrastructure was used to send phishing messages onward to new victims.

Who’s being targeted

  • Commonly targeted roles: Defense and aerospace engineering, R&D / researchers, Program and project management (defense programs), IT/SOC, Executives in defense/aerospace organizations.
  • Affected industries: Defense, Aerospace, UAV sector, Government contractors.
  • Attack channels: email, website.
  • Impersonated: Lockheed Martin (job opportunity / recruiter outreach), Enveil (impersonated via lookalike websites).

Red flags to watch for

  • Unsolicited job outreach that requires installing or running a viewer to read a job description
  • Archive contains executables/DLLs instead of a simple PDF
  • Pressure to open a provided file rather than viewing the role on an official careers site
  • Software download requested as part of a recruiting process
  • Brand mismatch or unfamiliar third-party tool required to view a PDF
  • Website is an impersonation/lookalike rather than the real company domain
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did Lazarus Group trick defense professionals in this campaign?

Attackers sent convincing fake job offers, including a Lockheed Martin job description, that asked targets to open a PDF viewer packaged with the file. That viewer contained a malicious DLL or was itself trojanized.

What was the role of the Windows zero-day in this attack?

The zero-day, tracked as CVE-2026-68820, let attackers gain full control of infected computers and evade EDR visibility. Microsoft shipped a fix in the August 2026 Patch Tuesday update.

Why did the fake job offers seem trustworthy?

Attackers hijacked legitimate but compromised websites and webmail servers, including Roundcube and WordPress installations, to relay commands and make traffic blend in with normal activity.

What should defense and aerospace employees watch for?

Be wary of unsolicited recruiter outreach that requires installing a special PDF viewer or downloading software to read a job description, and verify recruiters through official channels.

Read the video transcript

You get an email: “Lockheed Martin job opportunity, open the attached description with the included PDF viewer.” Sounds flattering, right? This is Operation Dream Job from the Lazarus group: you download an encrypted archive, run their “PDF viewer,” and a hidden DLL pops up a real-looking Lockheed job while quietly exploiting a Windows zero-day, CVE-2026-68820. They even push a fake “SecurityPDF” download from sites impersonating Enveil, and route traffic through hijacked Roundcube and WordPress servers so it all looks legit in your logs. Aha moment: any recruiter who makes you install a special viewer is a no. Your move: stop, don’t run it, go to the official careers site or company HR contact and verify the job there.

Similar attacks

Fake Job Offers Spread Lazarus Zero-Day Attack

Fake Job Offers Spread Lazarus Zero-Day Attack

Researchers describe a real, ongoing Lazarus-linked campaign where targets are lured with attractive job offers and tricked into downloading a PDF viewer and “job description” documents. Opening the files installs backdoors and, in at least one wave, attackers used a Windows zero-day to gain deep…

August 11, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026
Lazarus “Dream Job” Lures Spread Zero-Day Attack

Lazarus “Dream Job” Lures Spread Zero-Day Attack

Check Point and Microsoft report North Korea’s Lazarus Group used a long-running “Dream Job” social engineering campaign to target defense-sector job seekers with fake employer sites and trojanized documents/software. Victims were lured into opening malicious PDFs or installing a modified PDF…

August 11, 2026
Lazarus Job Offers Led to Windows Zero-Day

Lazarus Job Offers Led to Windows Zero-Day

North Korea’s Lazarus group targeted defense and aerospace staff using fraudulent job offers and fake websites, then deployed malware that pulled down and ran a Windows zero-day exploit. The campaign also used websites impersonating Enveil to distribute a trojanized PDF viewer that delivered a new…

August 12, 2026
Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026