Lazarus Job Offers Led to Windows Zero-Day

Infosecurity Magazine · High sophistication
Last updated August 12, 2026

North Korea’s Lazarus group targeted defense and aerospace staff using fraudulent job offers and fake websites, then deployed malware that pulled down and ran a Windows zero-day exploit. The campaign also used websites impersonating Enveil to distribute a trojanized PDF viewer that delivered a new backdoor.

Key findings

  • This was part of Lazarus’s long-running “Operation Dream Job,” using fraudulent job offers to approach defense-industry employees.
  • Targets were defense and aerospace-related organizations across Europe and India, including work on “surveillance sensors, drones and robotics.”
  • Attackers also created websites impersonating the privacy technology vendor Enveil and used them to distribute a trojanized PDF viewer.
  • The malware chain ultimately fetched and executed a Windows zero-day exploit (CVE-2026-68820), which Microsoft flagged as under active exploitation.
  • Command-and-control infrastructure leveraged compromised third-party servers (Roundcube and PrestaShop), rather than attacker-owned hosting.

Who’s being targeted

  • Commonly targeted roles: Engineering, R&D, Aerospace/Defense program teams, HR/Recruiting, IT Helpdesk, Security Awareness.
  • Affected industries: Defense, Aerospace, Robotics, Surveillance/Sensors.
  • Attack channels: email, website.
  • Impersonated: Recruiter / hiring team for a defense-related role, Enveil (impersonated).

Awareness takeaways

  • Treat unsolicited recruiter outreach for sensitive roles as high-risk and verify it through a known, trusted channel before opening any files or links.
  • Do not install ‘special viewers’ or tools to open documents from unknown sources; route these requests to IT/Security for validation.
  • Be cautious about lookalike vendor sites (even if they appear in search results) and confirm the official domain before downloading software.
  • Defense and aerospace teams should assume they are specifically targeted and use extra scrutiny for job-related, vendor-related, and document-related outreach.

Red flags to watch for

  • Unsolicited job offer sent to a work inbox tied to defense/aerospace work
  • Pressure to open “crafted documents” or install a viewer to read them
  • Unexpected links/attachments related to hiring that don’t match normal HR processes
  • Vendor website lookalike/typosquatting behavior (impersonation)
  • Software download required just to view documents
  • Search results leading to an unexpected ‘top-ranked’ site for a niche vendor
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get this in your work inbox: “Hi, I’m reaching out with a job opportunity…” for drones and surveillance roles. Looks flattering, right? This is Lazarus’s “Operation Dream Job.” They send you fake offers, then push you to open crafted documents or install a special PDF viewer from a site that looks like Enveil. That viewer quietly pulls a Windows zero-day exploit, CVE-2026-68820. Here’s the trap: unsolicited recruiter email to your work address, pressure to open their crafted docs, and “you must install our viewer” from a search result that magically ranks first for a niche vendor like Enveil. That combo is the tell. If a recruiter or vendor email wants you to open special docs or install a viewer, stop and forward it to Security, let them open that ‘dream job’ first.

Similar attacks

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools,…

August 13, 2026
Fake Job Offers Spread Lazarus Zero-Day Attack

Fake Job Offers Spread Lazarus Zero-Day Attack

Researchers describe a real, ongoing Lazarus-linked campaign where targets are lured with attractive job offers and tricked into downloading a PDF viewer and “job description” documents. Opening the files installs backdoors and, in at least one wave, attackers used a Windows zero-day to gain deep…

August 11, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026
Lazarus “Dream Job” Lures Spread Zero-Day Attack

Lazarus “Dream Job” Lures Spread Zero-Day Attack

Check Point and Microsoft report North Korea’s Lazarus Group used a long-running “Dream Job” social engineering campaign to target defense-sector job seekers with fake employer sites and trojanized documents/software. Victims were lured into opening malicious PDFs or installing a modified PDF…

August 11, 2026
Fake Download Sites Hijack Clicks to Drop Malware

Fake Download Sites Hijack Clicks to Drop Malware

Researchers and a Windows app developer uncovered a campaign using lookalike “official” software download websites that rank highly in Google results. The sites initially serve legitimate downloads to build trust, then quietly swap the download links to malware that can steal credentials and…

July 29, 2026