This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and trojanized software to infect defense organizations, an approach that can be recreated for employee training.
How the Attacks Worked
Two distinct but related patterns emerge from this reporting. In the first, an employee at IEH Corporation, a defense and aerospace component manufacturer, received a fraudulent document-sharing link. Clicking it led to a fake Microsoft 365 login page, and entering credentials there gave attackers access to the mailbox. This type of attack does not rely on malware at all, just a convincing pretext and a login prompt.
In the second pattern, tied to the Lazarus-linked Operation Dream Job, attackers used fake job opportunities to reach engineers and defense program staff. Instead of a credential-harvesting link, the payload was trojanized 'PDF software' that, once opened, deployed malware onto the target's system.
A third data point, from Levi Strauss & Co., shows that social engineering does not need to involve a phishing link or malware installer at all. Attackers used social engineering to compromise three employee devices directly and steal corporate information.
Why These Attacks Succeeded
Each scenario exploits a routine workplace behavior that employees rarely question:
- Reviewing a shared document from what looks like a business contact
- Considering a job opportunity that appears relevant to their skills
- Trusting normal-seeming requests without independent verification
Because these pretexts mimic everyday tasks, such as viewing files or reviewing career opportunities, they bypass the skepticism people typically reserve for obviously suspicious emails.
What to Watch For
Defenders and employees should be alert to:
- Unexpected document shares tied to purchase orders, engineering files, or contracts you weren't expecting
- Links that lead to a login prompt asking for corporate credentials rather than displaying a file directly
- Unsolicited job offers, especially for sensitive or defense-related roles, that ask you to install or run unfamiliar software
- Any message creating urgency to review documents or respond to a job offer quickly
Building Resistance
Organizations, particularly in defense, aerospace, and manufacturing, can reduce risk by training employees to verify unexpected document-share requests before entering credentials, and to treat unsolicited recruiting outreach with the same scrutiny as any unknown attachment. Reporting suspicious interactions immediately, even when no data appears to have been exposed, helps security teams respond before an initial compromise escalates. Since these incidents show that both credential phishing and direct social engineering can lead to real corporate data loss, awareness training should cover both technical red flags, like unexpected login prompts, and human-behavior red flags, like recruiter contact regarding roles the employee did not apply for.
Key findings
- Levi Strauss reported attackers used social engineering to compromise three employee devices and steal corporate information.
- IEH Corporation confirmed a phishing compromise of an employee’s Microsoft 365 mailbox using a fraudulent document-sharing link to steal credentials.
- Operation Dream Job (Lazarus-linked) used fraudulent job opportunities and trojanized PDF software to deploy malware against defense organizations.
Who’s being targeted
- Commonly targeted roles: All employees, Engineering, Defense/Aerospace program teams, HR/Recruiting, Executives, IT/Helpdesk.
- Affected industries: Government, Healthcare, Retail/Apparel, Defense/Aerospace Manufacturing, Energy.
- Attack channels: email.
- Impersonated: Document-sharing service / business contact, Recruiter / hiring team for a job opportunity.
Red flags to watch for
- Unexpected document share or purchase/engineering context you weren’t expecting
- Link leads to a login prompt asking for corporate credentials
- Sender pressure or urgency to review documents quickly
- Unsolicited job offer tied to sensitive/defense roles
- Request to install or run “PDF software” rather than using standard PDF viewing
- Unexpected attachments or installers presented as recruiting materials
Frequently asked questions
How did attackers compromise IEH Corporation?
Attackers sent a fraudulent document-sharing link that led an employee to a fake login page, stealing their Microsoft 365 credentials and potentially exposing engineering and export-controlled data.
What is Operation Dream Job?
Operation Dream Job is a Lazarus-linked campaign that uses fraudulent job opportunities and trojanized PDF software to deploy malware against defense organizations in Europe, India, and Brazil.
Did Levi Strauss suffer a data breach?
Levi Strauss reported that attackers used social engineering to compromise three employee devices and steal corporate information.
What red flags indicate a document-sharing phishing attempt?
Watch for unexpected document shares, links that prompt a corporate login, and messages that pressure you to act quickly on unfamiliar purchase or engineering content.
Read the video transcript
Levi Strauss and a defense supplier were breached the same way: someone trusted a link and a file they shouldn't have. At IEH, a defense manufacturer, one click on a fake document‑sharing link led to a Microsoft 365 login page. The employee entered their password, and their mailbox, and sensitive engineering documents, were exposed. In Operation Dream Job, targets get an email from a 'recruiter' for a sensitive defense role. The catch: to see the job details, you have to install their special 'PDF software', which is actually malware. Aha moment: if a link or job email makes you log in or install software unexpectedly, stop. Do not click or install, forward it to the security team and ask them to check it.