Fake Recruiters Target Job Seekers With Malicious PDFs

The Record · High sophistication
Last updated August 12, 2026

North Korea-linked Lazarus Group ran a “Dream Job” campaign targeting people applying for defense and aerospace jobs by posing as recruiters on LinkedIn and other platforms. Victims were sent malicious PDF files; opening them enabled a backdoor and then an exploit for a Windows zero-day (CVE-2026-68820) to gain deeper control of the device.

Key findings

  • CISA ordered federal agencies to patch a Windows Winsock vulnerability (CVE-2026-68820) that Microsoft confirmed is exploited in real-world attacks.
  • The activity was linked to Operation “Dream Job,” a long-running DPRK campaign that exploits the job application process.
  • Check Point reported Lazarus Group impersonated recruiters for well-known companies and contacted victims on LinkedIn and other sites before sending malicious PDF files.
  • Opening the malicious PDFs enabled a backdoor for long-term remote access; the malware then deployed an exploit for CVE-2026-68820 to escalate control.
  • Researchers warned the campaign blended legitimate/trusted infrastructure (branding, search results, and compromised orgs) to make the lure appear authentic.

Who’s being targeted

  • Commonly targeted roles: Recruiting/HR, Employees on LinkedIn, Engineers, Defense/aerospace program staff, Executives, IT/Security operations.
  • Affected industries: Defense and aerospace, Defense manufacturing, Surveillance and sensors, Drones and robotics.
  • Attack channels: linkedin, email.
  • Impersonated: Recruiters from Lockheed Martin (and other named firms).

Awareness takeaways

  • Treat unsolicited recruiter outreach (especially for defense/aerospace roles) as a high-risk channel and verify the recruiter using trusted, independent contact paths before opening any files.
  • Do not open unexpected PDFs from newly contacted senders; a single opened document can enable long-term remote access.
  • Don’t rely only on “spot the phishing link” advice, attackers may use realistic branding and trusted-looking web infrastructure to make scams appear legitimate.

Red flags to watch for

  • Unsolicited recruiter contact that quickly pushes you to open a file
  • Unexpected PDF file from a new/unverified sender
  • Too-authentic feel relying on brand names and “trusted” infrastructure
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: a Lockheed Martin recruiter pings you on LinkedIn with a dream aerospace role and a PDF to review. That exact move is Operation 'Dream Job', Lazarus Group posing as Lockheed Martin and Enveil recruiters, sending malicious PDFs that, once opened, drop a backdoor and hit a Windows Winsock zero-day, CVE-2026-68820. The trap is how real it looks: big-name logos, polished profiles, even showing up in top search results. The only real tell? Unsolicited outreach that quickly pushes you to open an unexpected PDF from someone you’ve never actually verified. If a new recruiter sends you a PDF, pause. Don’t open it until you independently verify them through the company’s official careers site or switchboard, and only then ask for the file again.

Similar attacks

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Fake Job Offers Spread Lazarus Zero-Day Attack

Fake Job Offers Spread Lazarus Zero-Day Attack

Researchers describe a real, ongoing Lazarus-linked campaign where targets are lured with attractive job offers and tricked into downloading a PDF viewer and “job description” documents. Opening the files installs backdoors and, in at least one wave, attackers used a Windows zero-day to gain deep…

August 11, 2026
Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools,…

August 13, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026
Lazarus “Dream Job” Lures Spread Zero-Day Attack

Lazarus “Dream Job” Lures Spread Zero-Day Attack

Check Point and Microsoft report North Korea’s Lazarus Group used a long-running “Dream Job” social engineering campaign to target defense-sector job seekers with fake employer sites and trojanized documents/software. Victims were lured into opening malicious PDFs or installing a modified PDF…

August 11, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026