Lazarus “Dream Job” LinkedIn Recruiter Lures

About DFIR · High sophistication
Last updated August 14, 2026

A North Korea-linked threat group used fake recruiter outreach on LinkedIn to target defense and aerospace companies across multiple countries. The victims were tricked into opening a trojanized PDF viewer or a malicious archive, which led to backdoor installation and deeper system compromise.

How the Attack Worked

This Lazarus Group operation revived the long-running "Dream Job" playbook, using fake recruiter outreach on LinkedIn to reach employees at defense and aerospace firms in France, Germany, Brazil, and India. The pretext relied on a believable job opportunity message, encouraging the target to open a file described as containing job details. That file was either a trojanized PDF viewer or a malicious archive, and opening it deployed a new backdoor called Troy. From there, the operation used a Windows zero-day in the AFD.sys driver to gain SYSTEM privileges and load an updated rootkit, expanding the attacker's foothold well beyond the initial file execution.

Why It Succeeded

The approach worked because it targeted a normal, expected professional interaction: a recruiter reaching out about a job. Roles in engineering, R&D, program management, and recruiting/HR are used to receiving unsolicited messages about opportunities, which lowers suspicion around a first contact. The campaign also avoided easy detection at the network level by routing command-and-control traffic through compromised WordPress, SharePoint, and Roundcube servers, so the traffic looked like ordinary web activity rather than something tied to a backdoor.

What to Watch For

  • Unsolicited recruiter contact that quickly pushes toward opening a file rather than a normal conversation or application process
  • Job details delivered as a PDF viewer download or an archive instead of through a standard hiring platform
  • Pressure to review materials outside established recruiting or HR channels
  • Network or web traffic that looks legitimate on the surface but originates from unexpected recruiter contact

Building Resistance

Organizations in defense and aerospace, and any industry targeted by long-term espionage-style campaigns, should treat unsolicited recruiter outreach as a high-risk channel by default. Employees should be encouraged to verify a recruiter or hiring company through trusted, independent sources before engaging further, and to avoid opening job description files or archives sent directly through LinkedIn messages. Moving any serious conversation to validated corporate recruiting channels before exchanging documents removes the opportunity for a trojanized file to ever reach a device. Finally, security teams should reinforce that normal-looking web traffic is not proof of safety, since attackers can route activity through legitimate but compromised infrastructure to avoid raising alarms. This campaign, associated with techniques like T1566.003 spearphishing via service and T1204.002 malicious file execution, shows how a familiar social interaction can be turned into a serious intrusion vector when awareness and verification habits are not part of the process.

Key findings

  • Lazarus ran a new wave of its “Dream Job” campaign using fake recruiter outreach on LinkedIn.
  • Targets included defense and aerospace firms in France, Germany, Brazil, and India.
  • Victims were lured into opening a trojanized PDF viewer or a malicious archive that deployed a new backdoor (“Troy”).
  • The operation also leveraged a Windows zero-day in AFD.sys to gain SYSTEM privileges and load an updated rootkit (FudModule).
  • Command-and-control traffic was routed through compromised WordPress, SharePoint, and Roundcube servers to blend in with normal web activity.

Who’s being targeted

  • Commonly targeted roles: Engineering, R&D, Recruiting/HR, Program Management, Executives in defense/aerospace.
  • Affected industries: Defense, Aerospace.
  • Attack channels: linkedin.
  • Impersonated: External recruiter / talent acquisition.

Red flags to watch for

  • Unsolicited recruiter contact pushing you to open a file
  • Use of nonstandard attachments or archives for “job details”
  • Pressure to review materials outside normal hiring platforms/processes
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the Lazarus Dream Job campaign?

It is a recurring social engineering operation by the Lazarus Group that uses fake recruiter outreach on LinkedIn to lure targets into opening malicious files, in this wave aimed at defense and aerospace firms in France, Germany, Brazil, and India.

How did victims get compromised?

Victims were lured into opening a trojanized PDF viewer or a malicious archive that deployed a new backdoor called Troy, which then led to deeper system compromise.

Why was this campaign hard to detect?

Command-and-control traffic was routed through compromised WordPress, SharePoint, and Roundcube servers, allowing malicious activity to blend in with normal web traffic.

What should employees watch for from recruiter messages?

Treat unsolicited recruiter outreach as high risk, avoid opening job description files or archives shared over LinkedIn, and verify recruiters through trusted channels before engaging.

Read the video transcript

You get a LinkedIn message: “Dream job in aerospace, perfect for your background. Open the attached PDF viewer for details.” Sounds great, right? Behind that “viewer” is Lazarus’s Dream Job campaign. One click can install their Troy backdoor, exploit a Windows AFD.sys zero-day, and drop a FudModule rootkit, while traffic hides behind normal-looking WordPress and SharePoint sites. The tell: real recruiters don’t send random EXEs or zip archives in LinkedIn chat. If a “talent acquisition” contact is pushing you to open a special viewer or archive for job details, that’s your red flag. If a LinkedIn recruiter sends you any file to open, stop. Don’t touch the file, verify the recruiter and role through our HR or the company’s official careers site first.

Similar attacks

Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Rust Maintainers Phished via Fake “Conference Call”

Rust Maintainers Phished via Fake “Conference Call”

An unknown group suspected to be North Korean state hackers targeted Rust language team members and high-profile package (“crate”) maintainers with phishing that lures victims into a fake conference call. When the victim tries to join, they are told they must install a “video codec” or update…

September 25, 2026
Device-Code Phish + Fake Recruiter Interview Lures

Device-Code Phish + Fake Recruiter Interview Lures

This news roundup describes multiple real-world social engineering operations, including a device-code phishing service that stole access to over 12,000 inboxes and a North Korean campaign posing as recruiters to trick developers during fake coding interviews. The attackers used legitimate login…

September 24, 2026
Fake AI Recruiters Hit 30K Devices Worldwide

Fake AI Recruiters Hit 30K Devices Worldwide

A weekly threat bulletin highlights a North Korea–linked campaign where attackers posed as AI or blockchain employers to trick IT professionals into getting infected and losing cryptocurrency. It also notes a phishing kit that abuses Microsoft’s legitimate device login flow to gain long-lasting…

September 22, 2026
Fake LastPass Download on GitHub Drops Stealer

Fake LastPass Download on GitHub Drops Stealer

Researchers found attackers impersonating LastPass with a fake GitHub “LastPass Authenticator” download page that tricks people into downloading a large ZIP and running a fake installer. The installer uses a Microsoft-signed Windows driver to shut down antivirus/EDR tools, then runs a password…

September 21, 2026