Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can lead to full control of the computer.
How the attack worked
This campaign, tied to the long-running Operation Dream Job effort attributed to the Lazarus Group, relies on convincing recruiter outreach rather than technical exploits alone. Attackers approach professionals, particularly in defense and aerospace roles across France, Germany, Brazil, and India, with fake-but-compelling job offers that reference well-known employer brands. Once trust is established, the conversation moves toward a job description PDF or similar document.
Two infection paths have been observed. In one, victims download an encrypted archive that leads to DLL side-loading. In the other, victims are told they need a special viewer to open the document and are directed to download a trojanized "SecurityPDF" application from a website impersonating Enveil. At least three lookalike domains were created to distribute this fake viewer. Once installed, the malware deploys backdoors that give attackers remote access and the ability to bypass security controls.
Why it succeeded
The approach works because it exploits normal professional behavior rather than obvious technical red flags. Job-seeking engineers and researchers are primed to expect documents, links, and even software recommendations from recruiters. By referencing recognizable employer names and using a professional-looking impersonation site, the attackers reduced suspicion at each step.
- Recruiter outreach on LinkedIn built initial trust before any file was sent
- Victims were told a specific viewer was required to open the document, adding a plausible reason to install new software
- Lookalike domains and vendor branding made the download source appear legitimate
What to watch for
- Unsolicited recruiter messages that quickly move toward sending files or requesting software installation
- Instructions to download a special viewer or app just to open a PDF
- Job offers referencing recognizable companies without verifiable recruiter details
- Download links pointing to domains that closely resemble, but do not exactly match, a known vendor's name
How to build resistance
Organizations in defense, aerospace, and related supply chains should train staff, especially engineers, researchers, and program managers, to treat unsolicited recruiter contact as a high-risk channel. Employees should verify recruiters and employers independently before exchanging files, and should never install a viewer or tool suggested by a new contact to open a document. IT and security teams should reinforce that software should only come from official vendor channels, not from search results or links shared during unsolicited conversations. Related MITRE ATT&CK techniques include spearphishing attachment (T1566.001), spearphishing via service (T1566.002), and user execution via malicious file (T1204.002).
Key findings
- Campaign attributed to Lazarus Group (North Korea) as part of the long-running “Operation Dream Job” social engineering effort.
- Targets include defense and aerospace companies across France, Germany, Brazil, and India.
- Victims are approached with fake recruiter messages and job offers (including impersonation of well-known brands) to build trust.
- Two observed infection paths: (1) victims download an encrypted archive leading to DLL side-loading; (2) victims download and install a trojanized PDF viewer (“SecurityPDF”) from websites impersonating Enveil.
- Attackers created at least three Enveil-impersonation domains to distribute the trojanized viewer: envell[.]xyz, enveil[.]online, uxtramine[.]org.
- The article states attackers may send the PDF first, then pressure the victim to download the PDF viewer to open it.
- Once installed/triggered, malware deploys backdoors (ForestTiger/ScoringMathTea and Troy), enabling remote access and data theft.
Who’s being targeted
- Commonly targeted roles: Aerospace/Defense employees, Engineering, R&D, Recruiting/HR, Executives, IT support / Endpoint management.
- Affected industries: Defense, Aerospace, Government contractors, Critical infrastructure supply chain.
- Attack channels: linkedin, email, website.
- Impersonated: Recruiters (posing as legitimate recruiters tied to well-known firms), Recruiter, Enveil (impersonated vendor branding/portal).
Red flags to watch for
- Unsolicited recruiter outreach that quickly pushes files/software
- A recruiter asks you to open a document using a specific viewer/app
- Brand-name employer references used to build trust without verifiable details
- Unexpected PDF from a new contact tied to a job offer
- Instruction to install software just to view a document
- File/viewer provided through non-standard channels rather than official company sites
- Software download comes from a site found via search results instead of official vendor channels
- Domain name is close to the real brand (lookalike spelling)
- Instructions emphasize urgency to install a viewer to open a document
Frequently asked questions
How does the Lazarus Group fake job scam work?
Attackers pose as recruiters on platforms like LinkedIn, offer compelling fake job opportunities at well-known firms, and then push victims to open a malicious PDF or install a trojanized PDF viewer that installs backdoors.
What is 'SecurityPDF' in this campaign?
SecurityPDF is a trojanized PDF viewer distributed from websites impersonating the vendor Enveil, which victims are told they need to install in order to view a job-related document.
Who is being targeted in this campaign?
The campaign has targeted defense and aerospace companies across France, Germany, Brazil, and India, focusing on engineers, researchers, program managers, and other aerospace/defense staff.
What happens after the malware is installed?
The malware deploys backdoors, referred to as ForestTiger/ScoringMathTea and Troy, that give attackers remote access to the infected computer and the ability to steal data.
Read the video transcript
You get a LinkedIn message: a recruiter offering a dream role at Lockheed Martin or Enveil, out of nowhere. This is Lazarus Group’s “Operation Dream Job”: they send a job PDF, then pressure you to install a special viewer called SecurityPDF from sites like envell.xyz or enveil.online. The moment you run that viewer, it quietly drops backdoors like ForestTiger and Troy, giving them remote access to your machine and your company’s data. If any recruiter ever tells you to install a special viewer or tool to open their job PDF, stop and report it to Security, do not install it, no matter how good the offer sounds.