North Korea-linked Lazarus Group ran a “Dream Job” campaign targeting people applying for defense and aerospace jobs by posing as recruiters on LinkedIn and other platforms. Victims were sent malicious PDF files; opening them enabled a backdoor and then an exploit for a Windows zero-day (CVE-2026-68820) to gain deeper control of the device.
Key findings
- CISA ordered federal agencies to patch a Windows Winsock vulnerability (CVE-2026-68820) that Microsoft confirmed is exploited in real-world attacks.
- The activity was linked to Operation “Dream Job,” a long-running DPRK campaign that exploits the job application process.
- Check Point reported Lazarus Group impersonated recruiters for well-known companies and contacted victims on LinkedIn and other sites before sending malicious PDF files.
- Opening the malicious PDFs enabled a backdoor for long-term remote access; the malware then deployed an exploit for CVE-2026-68820 to escalate control.
- Researchers warned the campaign blended legitimate/trusted infrastructure (branding, search results, and compromised orgs) to make the lure appear authentic.
Who’s being targeted
- Commonly targeted roles: Recruiting/HR, Employees on LinkedIn, Engineers, Defense/aerospace program staff, Executives, IT/Security operations.
- Affected industries: Defense and aerospace, Defense manufacturing, Surveillance and sensors, Drones and robotics.
- Attack channels: linkedin, email.
- Impersonated: Recruiters from Lockheed Martin (and other named firms).
Awareness takeaways
- Treat unsolicited recruiter outreach (especially for defense/aerospace roles) as a high-risk channel and verify the recruiter using trusted, independent contact paths before opening any files.
- Do not open unexpected PDFs from newly contacted senders; a single opened document can enable long-term remote access.
- Don’t rely only on “spot the phishing link” advice, attackers may use realistic branding and trusted-looking web infrastructure to make scams appear legitimate.
Red flags to watch for
- Unsolicited recruiter contact that quickly pushes you to open a file
- Unexpected PDF file from a new/unverified sender
- Too-authentic feel relying on brand names and “trusted” infrastructure
Read the video transcript
Imagine this: a Lockheed Martin recruiter pings you on LinkedIn with a dream aerospace role and a PDF to review. That exact move is Operation 'Dream Job', Lazarus Group posing as Lockheed Martin and Enveil recruiters, sending malicious PDFs that, once opened, drop a backdoor and hit a Windows Winsock zero-day, CVE-2026-68820. The trap is how real it looks: big-name logos, polished profiles, even showing up in top search results. The only real tell? Unsolicited outreach that quickly pushes you to open an unexpected PDF from someone you’ve never actually verified. If a new recruiter sends you a PDF, pause. Don’t open it until you independently verify them through the company’s official careers site or switchboard, and only then ask for the file again.