Lazarus “Dream Job” LinkedIn Recruiter Lures

About DFIR · High sophistication
Last updated August 14, 2026

A North Korea-linked threat group used fake recruiter outreach on LinkedIn to target defense and aerospace companies across multiple countries. The victims were tricked into opening a trojanized PDF viewer or a malicious archive, which led to backdoor installation and deeper system compromise.

How the Attack Worked

This Lazarus Group operation revived the long-running "Dream Job" playbook, using fake recruiter outreach on LinkedIn to reach employees at defense and aerospace firms in France, Germany, Brazil, and India. The pretext relied on a believable job opportunity message, encouraging the target to open a file described as containing job details. That file was either a trojanized PDF viewer or a malicious archive, and opening it deployed a new backdoor called Troy. From there, the operation used a Windows zero-day in the AFD.sys driver to gain SYSTEM privileges and load an updated rootkit, expanding the attacker's foothold well beyond the initial file execution.

Why It Succeeded

The approach worked because it targeted a normal, expected professional interaction: a recruiter reaching out about a job. Roles in engineering, R&D, program management, and recruiting/HR are used to receiving unsolicited messages about opportunities, which lowers suspicion around a first contact. The campaign also avoided easy detection at the network level by routing command-and-control traffic through compromised WordPress, SharePoint, and Roundcube servers, so the traffic looked like ordinary web activity rather than something tied to a backdoor.

What to Watch For

  • Unsolicited recruiter contact that quickly pushes toward opening a file rather than a normal conversation or application process
  • Job details delivered as a PDF viewer download or an archive instead of through a standard hiring platform
  • Pressure to review materials outside established recruiting or HR channels
  • Network or web traffic that looks legitimate on the surface but originates from unexpected recruiter contact

Building Resistance

Organizations in defense and aerospace, and any industry targeted by long-term espionage-style campaigns, should treat unsolicited recruiter outreach as a high-risk channel by default. Employees should be encouraged to verify a recruiter or hiring company through trusted, independent sources before engaging further, and to avoid opening job description files or archives sent directly through LinkedIn messages. Moving any serious conversation to validated corporate recruiting channels before exchanging documents removes the opportunity for a trojanized file to ever reach a device. Finally, security teams should reinforce that normal-looking web traffic is not proof of safety, since attackers can route activity through legitimate but compromised infrastructure to avoid raising alarms. This campaign, associated with techniques like T1566.003 spearphishing via service and T1204.002 malicious file execution, shows how a familiar social interaction can be turned into a serious intrusion vector when awareness and verification habits are not part of the process.

Key findings

  • Lazarus ran a new wave of its “Dream Job” campaign using fake recruiter outreach on LinkedIn.
  • Targets included defense and aerospace firms in France, Germany, Brazil, and India.
  • Victims were lured into opening a trojanized PDF viewer or a malicious archive that deployed a new backdoor (“Troy”).
  • The operation also leveraged a Windows zero-day in AFD.sys to gain SYSTEM privileges and load an updated rootkit (FudModule).
  • Command-and-control traffic was routed through compromised WordPress, SharePoint, and Roundcube servers to blend in with normal web activity.

Who’s being targeted

  • Commonly targeted roles: Engineering, R&D, Recruiting/HR, Program Management, Executives in defense/aerospace.
  • Affected industries: Defense, Aerospace.
  • Attack channels: linkedin.
  • Impersonated: External recruiter / talent acquisition.

Red flags to watch for

  • Unsolicited recruiter contact pushing you to open a file
  • Use of nonstandard attachments or archives for “job details”
  • Pressure to review materials outside normal hiring platforms/processes
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Lazarus Dream Job campaign?

It is a recurring social engineering operation by the Lazarus Group that uses fake recruiter outreach on LinkedIn to lure targets into opening malicious files, in this wave aimed at defense and aerospace firms in France, Germany, Brazil, and India.

How did victims get compromised?

Victims were lured into opening a trojanized PDF viewer or a malicious archive that deployed a new backdoor called Troy, which then led to deeper system compromise.

Why was this campaign hard to detect?

Command-and-control traffic was routed through compromised WordPress, SharePoint, and Roundcube servers, allowing malicious activity to blend in with normal web traffic.

What should employees watch for from recruiter messages?

Treat unsolicited recruiter outreach as high risk, avoid opening job description files or archives shared over LinkedIn, and verify recruiters through trusted channels before engaging.

Read the video transcript

You get a LinkedIn message: “Dream job in aerospace, perfect for your background. Open the attached PDF viewer for details.” Sounds great, right? Behind that “viewer” is Lazarus’s Dream Job campaign. One click can install their Troy backdoor, exploit a Windows AFD.sys zero-day, and drop a FudModule rootkit, while traffic hides behind normal-looking WordPress and SharePoint sites. The tell: real recruiters don’t send random EXEs or zip archives in LinkedIn chat. If a “talent acquisition” contact is pushing you to open a special viewer or archive for job details, that’s your red flag. If a LinkedIn recruiter sends you any file to open, stop. Don’t touch the file, verify the recruiter and role through our HR or the company’s official careers site first.

Similar attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Steam Forum “Fix” Posts Push Malicious PowerShell

Steam Forum “Fix” Posts Push Malicious PowerShell

Attackers used fake Steam forum replies that looked like helpful troubleshooting steps for real gaming/PC problems. The posts tricked users into running PowerShell as an administrator, which then downloaded and installed the XMRig crypto miner and set it to run automatically at startup. The…

July 29, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Teams “Update” Led to $630K Crypto Theft

Fake Teams “Update” Led to $630K Crypto Theft

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft Teams call link. After the call “had no working audio,” the victim approved what looked like a Teams update, which installed a malicious…

July 21, 2026
Fake Slack Job Posts Push Trojan Coding Tests

Fake Slack Job Posts Push Trojan Coding Tests

North Korea–linked actors used fake developer job offers inside a Slack community to trick targets into running a “coding assessment” project. The repository looked legitimate but secretly assembled malware hidden in SVG flag images, leading to credential, file, crypto-wallet, and clipboard theft…

July 17, 2026