North Korea’s Lazarus group targeted defense and aerospace staff using fraudulent job offers and fake websites, then deployed malware that pulled down and ran a Windows zero-day exploit. The campaign also used websites impersonating Enveil to distribute a trojanized PDF viewer that delivered a new backdoor.
Key findings
- This was part of Lazarus’s long-running “Operation Dream Job,” using fraudulent job offers to approach defense-industry employees.
- Targets were defense and aerospace-related organizations across Europe and India, including work on “surveillance sensors, drones and robotics.”
- Attackers also created websites impersonating the privacy technology vendor Enveil and used them to distribute a trojanized PDF viewer.
- The malware chain ultimately fetched and executed a Windows zero-day exploit (CVE-2026-68820), which Microsoft flagged as under active exploitation.
- Command-and-control infrastructure leveraged compromised third-party servers (Roundcube and PrestaShop), rather than attacker-owned hosting.
Who’s being targeted
- Commonly targeted roles: Engineering, R&D, Aerospace/Defense program teams, HR/Recruiting, IT Helpdesk, Security Awareness.
- Affected industries: Defense, Aerospace, Robotics, Surveillance/Sensors.
- Attack channels: email, website.
- Impersonated: Recruiter / hiring team for a defense-related role, Enveil (impersonated).
Awareness takeaways
- Treat unsolicited recruiter outreach for sensitive roles as high-risk and verify it through a known, trusted channel before opening any files or links.
- Do not install ‘special viewers’ or tools to open documents from unknown sources; route these requests to IT/Security for validation.
- Be cautious about lookalike vendor sites (even if they appear in search results) and confirm the official domain before downloading software.
- Defense and aerospace teams should assume they are specifically targeted and use extra scrutiny for job-related, vendor-related, and document-related outreach.
Red flags to watch for
- Unsolicited job offer sent to a work inbox tied to defense/aerospace work
- Pressure to open “crafted documents” or install a viewer to read them
- Unexpected links/attachments related to hiring that don’t match normal HR processes
- Vendor website lookalike/typosquatting behavior (impersonation)
- Software download required just to view documents
- Search results leading to an unexpected ‘top-ranked’ site for a niche vendor
Read the video transcript
You get this in your work inbox: “Hi, I’m reaching out with a job opportunity…” for drones and surveillance roles. Looks flattering, right? This is Lazarus’s “Operation Dream Job.” They send you fake offers, then push you to open crafted documents or install a special PDF viewer from a site that looks like Enveil. That viewer quietly pulls a Windows zero-day exploit, CVE-2026-68820. Here’s the trap: unsolicited recruiter email to your work address, pressure to open their crafted docs, and “you must install our viewer” from a search result that magically ranks first for a niche vendor like Enveil. That combo is the tell. If a recruiter or vendor email wants you to open special docs or install a viewer, stop and forward it to Security, let them open that ‘dream job’ first.