Lazarus “Dream Job” Lures Spread Zero-Day Attack

The Register Security · High sophistication
Last updated August 11, 2026

Check Point and Microsoft report North Korea’s Lazarus Group used a long-running “Dream Job” social engineering campaign to target defense-sector job seekers with fake employer sites and trojanized documents/software. Victims were lured into opening malicious PDFs or installing a modified PDF viewer, which then delivered malware and supported follow-on exploitation of a Windows zero-day.

Key findings

  • The article links Lazarus’ “Operation Dream Job” to active exploitation observed in early June, alongside a Windows zero-day (CVE-2026-68820).
  • The lure is employment-related: fake job offers and impersonation of well-known companies to entice job seekers into clicking links or opening malicious documents.
  • Attackers used impersonation websites and SEO to increase credibility (including fake sites ranking highly in search results).
  • The campaign delivered malware through trojanized tooling: a modified PDF viewer (“SecurityPDF”) and attacker-crafted PDFs that execute a backdoor (“Troy”).
  • Targets highlighted include the defense sector in Europe and India, and impersonated brands included Lockheed Martin and Enveil.

Who’s being targeted

  • Commonly targeted roles: Recruiting/HR, Employees likely to be targeted as job candidates (Engineering, R&D, Defense programs), Executives and hiring managers at defense-related organizations, IT helpdesk / endpoint support (for user guidance on unsafe downloads).
  • Affected industries: Defense sector, Aerospace and defense contractors, Privacy/security technology.
  • Attack channels: website, email.
  • Impersonated: Enveil (impersonated careers/recruiting site), Recruiter for a high-profile employer (Dream Job theme).

Awareness takeaways

  • Treat unsolicited job offers as a phishing risk and verify recruiters via trusted channels before clicking links or opening files.
  • Don’t trust search rankings, verify company career sites carefully (bookmark known-good URLs and watch for lookalike domains).
  • Be suspicious when a “job process” requires installing special software (like a PDF viewer) to open documents.
  • Assume well-resourced actors can combine social engineering with technical exploits, so user reporting and rapid patching both matter.

Red flags to watch for

  • Lookalike/impersonation career site (even if it ranks highly in search results)
  • Download prompts for unusual software (e.g., a new PDF viewer) as part of a job process
  • Job-offer workflow relies on opening files from the site rather than verified recruiting channels
  • Unsolicited high-profile job offer with pressure to open documents/links
  • Unexpected attachment type or prompts to enable/install something to view the content
  • Sender identity doesn’t match verified corporate recruiting domains/channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Dream jobs impersonating Lockheed Martin or Enveil pop up in your inbox or top of Google. Looks legit, right? This is Lazarus’ “Dream Job” scam. They built fake Enveil career sites and push them up search results, then hand you a malicious PDF or a booby‑trapped viewer called SecurityPDF that runs their Troy backdoor. Here’s the tell: a high‑profile offer that suddenly needs you to install “SecurityPDF” or use some special viewer just to read an application. Real recruiters don’t make you install random tools for a PDF. If any job process asks you to install special software or a new PDF viewer, stop. Don’t install it, report it to Security immediately so we can check it out.

Similar attacks

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools,…

August 13, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026
Fake Job Offers Spread Lazarus Zero-Day Attack

Fake Job Offers Spread Lazarus Zero-Day Attack

Researchers describe a real, ongoing Lazarus-linked campaign where targets are lured with attractive job offers and tricked into downloading a PDF viewer and “job description” documents. Opening the files installs backdoors and, in at least one wave, attackers used a Windows zero-day to gain deep…

August 11, 2026
Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Microsoft says Russian-linked threat actors compromised hotel and conference guest Wi‑Fi “captive portal” networks to redirect travelers to fake Microsoft 365 sign-in pages, device-code phishing, or fake update pages. The goal was to steal cloud credentials (including Entra ID device codes) and…

August 4, 2026
Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026