Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools, and relied heavily on hijacked legitimate websites and webmail servers to blend in. Confirmed targets were found in multiple countries including France, Germany, Brazil, and India.
How the attack worked
This campaign, known as Operation Dream Job, targeted defense and aerospace professionals with fake job offers, including one referencing Lockheed Martin. Two infection paths were used. In one, victims downloaded an encrypted archive containing a legitimate signed PDF viewer bundled with a malicious DLL that displayed a convincing job description while quietly compromising the machine. In the other, victims were told to download a trojanized viewer called SecurityPDF from websites impersonating Enveil, a legitimate privacy technology company with no actual connection to the attack. Once installed, that modified viewer inspected any PDF opened through it for a hidden marker.
The role of the zero-day and hijacked infrastructure
The attackers used a previously unknown Windows vulnerability, CVE-2026-68820, to gain full control of infected systems and reduce visibility for security tools. Rather than running their own infrastructure, they relayed commands through hijacked legitimate websites and webmail servers, including compromised Roundcube and WordPress installations. In at least one case, infrastructure belonging to a previously breached organization was reused to send phishing messages onward to new victims, making detection harder because the traffic looked like normal, trusted activity.
Why it succeeded
The pretext relied on something professionals in defense and aerospace fields are conditioned to respond to: recruiting outreach for relevant, high-value roles. Requiring a special viewer to read a job description added a layer of plausibility, since defense-related documents are sometimes handled with dedicated tools. Combined with a signed viewer in one chain and a convincing lookalike brand in the other, the technical and social elements reinforced each other.
What to watch for
- Unsolicited recruiting messages that ask you to install or run a viewer just to read a job description
- Archives that contain executables or DLLs rather than a simple document
- Requests to download software from a website that is not the official company domain
- Job-related links or attachments arriving via webmail or websites that seem slightly off
Building resistance
Organizations in defense, aerospace, and government contracting should train staff to verify recruiter and company identity through known official channels before opening any attachment or installing any tool. Standard PDFs should never require a special viewer, and any request to do so should be treated as a red flag. Because this campaign relied on a real Windows zero-day, prioritizing fast patching for critical updates, including the August 2026 Patch Tuesday fix for CVE-2026-68820, remains an important complementary defense alongside awareness training.
Key findings
- Lazarus used fake job offers (including a Lockheed Martin job description) to trick targets into running malicious PDF-viewer software.
- The campaign exploited a Windows zero-day (CVE-2026-68820) to gain elevated control and reduce EDR visibility; Microsoft shipped a fix in August 2026 Patch Tuesday.
- Two infection chains were described: (1) encrypted archive with a legitimate signed PDF viewer plus a malicious DLL; (2) a trojanized “SecurityPDF” viewer downloaded from websites impersonating Enveil.
- Attackers relied on hijacked infrastructure (compromised websites, Roundcube webmail, WordPress) to make command-and-control traffic look legitimate.
- In at least one case, a previously breached French organization’s infrastructure was used to send phishing messages onward to new victims.
Who’s being targeted
- Commonly targeted roles: Defense and aerospace engineering, R&D / researchers, Program and project management (defense programs), IT/SOC, Executives in defense/aerospace organizations.
- Affected industries: Defense, Aerospace, UAV sector, Government contractors.
- Attack channels: email, website.
- Impersonated: Lockheed Martin (job opportunity / recruiter outreach), Enveil (impersonated via lookalike websites).
Red flags to watch for
- Unsolicited job outreach that requires installing or running a viewer to read a job description
- Archive contains executables/DLLs instead of a simple PDF
- Pressure to open a provided file rather than viewing the role on an official careers site
- Software download requested as part of a recruiting process
- Brand mismatch or unfamiliar third-party tool required to view a PDF
- Website is an impersonation/lookalike rather than the real company domain
Frequently asked questions
How did Lazarus Group trick defense professionals in this campaign?
Attackers sent convincing fake job offers, including a Lockheed Martin job description, that asked targets to open a PDF viewer packaged with the file. That viewer contained a malicious DLL or was itself trojanized.
What was the role of the Windows zero-day in this attack?
The zero-day, tracked as CVE-2026-68820, let attackers gain full control of infected computers and evade EDR visibility. Microsoft shipped a fix in the August 2026 Patch Tuesday update.
Why did the fake job offers seem trustworthy?
Attackers hijacked legitimate but compromised websites and webmail servers, including Roundcube and WordPress installations, to relay commands and make traffic blend in with normal activity.
What should defense and aerospace employees watch for?
Be wary of unsolicited recruiter outreach that requires installing a special PDF viewer or downloading software to read a job description, and verify recruiters through official channels.
Read the video transcript
You get an email: “Lockheed Martin job opportunity, open the attached description with the included PDF viewer.” Sounds flattering, right? This is Operation Dream Job from the Lazarus group: you download an encrypted archive, run their “PDF viewer,” and a hidden DLL pops up a real-looking Lockheed job while quietly exploiting a Windows zero-day, CVE-2026-68820. They even push a fake “SecurityPDF” download from sites impersonating Enveil, and route traffic through hijacked Roundcube and WordPress servers so it all looks legit in your logs. Aha moment: any recruiter who makes you install a special viewer is a no. Your move: stop, don’t run it, go to the official careers site or company HR contact and verify the job there.