A North Korea-linked threat group used fake recruiter outreach on LinkedIn to target defense and aerospace companies across multiple countries. The victims were tricked into opening a trojanized PDF viewer or a malicious archive, which led to backdoor installation and deeper system compromise.
How the Attack Worked
This Lazarus Group operation revived the long-running "Dream Job" playbook, using fake recruiter outreach on LinkedIn to reach employees at defense and aerospace firms in France, Germany, Brazil, and India. The pretext relied on a believable job opportunity message, encouraging the target to open a file described as containing job details. That file was either a trojanized PDF viewer or a malicious archive, and opening it deployed a new backdoor called Troy. From there, the operation used a Windows zero-day in the AFD.sys driver to gain SYSTEM privileges and load an updated rootkit, expanding the attacker's foothold well beyond the initial file execution.
Why It Succeeded
The approach worked because it targeted a normal, expected professional interaction: a recruiter reaching out about a job. Roles in engineering, R&D, program management, and recruiting/HR are used to receiving unsolicited messages about opportunities, which lowers suspicion around a first contact. The campaign also avoided easy detection at the network level by routing command-and-control traffic through compromised WordPress, SharePoint, and Roundcube servers, so the traffic looked like ordinary web activity rather than something tied to a backdoor.
What to Watch For
- Unsolicited recruiter contact that quickly pushes toward opening a file rather than a normal conversation or application process
- Job details delivered as a PDF viewer download or an archive instead of through a standard hiring platform
- Pressure to review materials outside established recruiting or HR channels
- Network or web traffic that looks legitimate on the surface but originates from unexpected recruiter contact
Building Resistance
Organizations in defense and aerospace, and any industry targeted by long-term espionage-style campaigns, should treat unsolicited recruiter outreach as a high-risk channel by default. Employees should be encouraged to verify a recruiter or hiring company through trusted, independent sources before engaging further, and to avoid opening job description files or archives sent directly through LinkedIn messages. Moving any serious conversation to validated corporate recruiting channels before exchanging documents removes the opportunity for a trojanized file to ever reach a device. Finally, security teams should reinforce that normal-looking web traffic is not proof of safety, since attackers can route activity through legitimate but compromised infrastructure to avoid raising alarms. This campaign, associated with techniques like T1566.003 spearphishing via service and T1204.002 malicious file execution, shows how a familiar social interaction can be turned into a serious intrusion vector when awareness and verification habits are not part of the process.
Key findings
- Lazarus ran a new wave of its “Dream Job” campaign using fake recruiter outreach on LinkedIn.
- Targets included defense and aerospace firms in France, Germany, Brazil, and India.
- Victims were lured into opening a trojanized PDF viewer or a malicious archive that deployed a new backdoor (“Troy”).
- The operation also leveraged a Windows zero-day in AFD.sys to gain SYSTEM privileges and load an updated rootkit (FudModule).
- Command-and-control traffic was routed through compromised WordPress, SharePoint, and Roundcube servers to blend in with normal web activity.
Who’s being targeted
- Commonly targeted roles: Engineering, R&D, Recruiting/HR, Program Management, Executives in defense/aerospace.
- Affected industries: Defense, Aerospace.
- Attack channels: linkedin.
- Impersonated: External recruiter / talent acquisition.
Red flags to watch for
- Unsolicited recruiter contact pushing you to open a file
- Use of nonstandard attachments or archives for “job details”
- Pressure to review materials outside normal hiring platforms/processes
Frequently asked questions
What is the Lazarus Dream Job campaign?
It is a recurring social engineering operation by the Lazarus Group that uses fake recruiter outreach on LinkedIn to lure targets into opening malicious files, in this wave aimed at defense and aerospace firms in France, Germany, Brazil, and India.
How did victims get compromised?
Victims were lured into opening a trojanized PDF viewer or a malicious archive that deployed a new backdoor called Troy, which then led to deeper system compromise.
Why was this campaign hard to detect?
Command-and-control traffic was routed through compromised WordPress, SharePoint, and Roundcube servers, allowing malicious activity to blend in with normal web traffic.
What should employees watch for from recruiter messages?
Treat unsolicited recruiter outreach as high risk, avoid opening job description files or archives shared over LinkedIn, and verify recruiters through trusted channels before engaging.
Read the video transcript
You get a LinkedIn message: “Dream job in aerospace, perfect for your background. Open the attached PDF viewer for details.” Sounds great, right? Behind that “viewer” is Lazarus’s Dream Job campaign. One click can install their Troy backdoor, exploit a Windows AFD.sys zero-day, and drop a FudModule rootkit, while traffic hides behind normal-looking WordPress and SharePoint sites. The tell: real recruiters don’t send random EXEs or zip archives in LinkedIn chat. If a “talent acquisition” contact is pushing you to open a special viewer or archive for job details, that’s your red flag. If a LinkedIn recruiter sends you any file to open, stop. Don’t touch the file, verify the recruiter and role through our HR or the company’s official careers site first.