Lazarus Lures Staff With Fake Jobs to Drop Malware

The Hacker News · High sophistication
Last updated August 14, 2026

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can lead to full control of the computer.

How the attack worked

This campaign, tied to the long-running Operation Dream Job effort attributed to the Lazarus Group, relies on convincing recruiter outreach rather than technical exploits alone. Attackers approach professionals, particularly in defense and aerospace roles across France, Germany, Brazil, and India, with fake-but-compelling job offers that reference well-known employer brands. Once trust is established, the conversation moves toward a job description PDF or similar document.

Two infection paths have been observed. In one, victims download an encrypted archive that leads to DLL side-loading. In the other, victims are told they need a special viewer to open the document and are directed to download a trojanized "SecurityPDF" application from a website impersonating Enveil. At least three lookalike domains were created to distribute this fake viewer. Once installed, the malware deploys backdoors that give attackers remote access and the ability to bypass security controls.

Why it succeeded

The approach works because it exploits normal professional behavior rather than obvious technical red flags. Job-seeking engineers and researchers are primed to expect documents, links, and even software recommendations from recruiters. By referencing recognizable employer names and using a professional-looking impersonation site, the attackers reduced suspicion at each step.

  • Recruiter outreach on LinkedIn built initial trust before any file was sent
  • Victims were told a specific viewer was required to open the document, adding a plausible reason to install new software
  • Lookalike domains and vendor branding made the download source appear legitimate

What to watch for

  • Unsolicited recruiter messages that quickly move toward sending files or requesting software installation
  • Instructions to download a special viewer or app just to open a PDF
  • Job offers referencing recognizable companies without verifiable recruiter details
  • Download links pointing to domains that closely resemble, but do not exactly match, a known vendor's name

How to build resistance

Organizations in defense, aerospace, and related supply chains should train staff, especially engineers, researchers, and program managers, to treat unsolicited recruiter contact as a high-risk channel. Employees should verify recruiters and employers independently before exchanging files, and should never install a viewer or tool suggested by a new contact to open a document. IT and security teams should reinforce that software should only come from official vendor channels, not from search results or links shared during unsolicited conversations. Related MITRE ATT&CK techniques include spearphishing attachment (T1566.001), spearphishing via service (T1566.002), and user execution via malicious file (T1204.002).

Key findings

  • Campaign attributed to Lazarus Group (North Korea) as part of the long-running “Operation Dream Job” social engineering effort.
  • Targets include defense and aerospace companies across France, Germany, Brazil, and India.
  • Victims are approached with fake recruiter messages and job offers (including impersonation of well-known brands) to build trust.
  • Two observed infection paths: (1) victims download an encrypted archive leading to DLL side-loading; (2) victims download and install a trojanized PDF viewer (“SecurityPDF”) from websites impersonating Enveil.
  • Attackers created at least three Enveil-impersonation domains to distribute the trojanized viewer: envell[.]xyz, enveil[.]online, uxtramine[.]org.
  • The article states attackers may send the PDF first, then pressure the victim to download the PDF viewer to open it.
  • Once installed/triggered, malware deploys backdoors (ForestTiger/ScoringMathTea and Troy), enabling remote access and data theft.

Who’s being targeted

  • Commonly targeted roles: Aerospace/Defense employees, Engineering, R&D, Recruiting/HR, Executives, IT support / Endpoint management.
  • Affected industries: Defense, Aerospace, Government contractors, Critical infrastructure supply chain.
  • Attack channels: linkedin, email, website.
  • Impersonated: Recruiters (posing as legitimate recruiters tied to well-known firms), Recruiter, Enveil (impersonated vendor branding/portal).

Red flags to watch for

  • Unsolicited recruiter outreach that quickly pushes files/software
  • A recruiter asks you to open a document using a specific viewer/app
  • Brand-name employer references used to build trust without verifiable details
  • Unexpected PDF from a new contact tied to a job offer
  • Instruction to install software just to view a document
  • File/viewer provided through non-standard channels rather than official company sites
  • Software download comes from a site found via search results instead of official vendor channels
  • Domain name is close to the real brand (lookalike spelling)
  • Instructions emphasize urgency to install a viewer to open a document
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the Lazarus Group fake job scam work?

Attackers pose as recruiters on platforms like LinkedIn, offer compelling fake job opportunities at well-known firms, and then push victims to open a malicious PDF or install a trojanized PDF viewer that installs backdoors.

What is 'SecurityPDF' in this campaign?

SecurityPDF is a trojanized PDF viewer distributed from websites impersonating the vendor Enveil, which victims are told they need to install in order to view a job-related document.

Who is being targeted in this campaign?

The campaign has targeted defense and aerospace companies across France, Germany, Brazil, and India, focusing on engineers, researchers, program managers, and other aerospace/defense staff.

What happens after the malware is installed?

The malware deploys backdoors, referred to as ForestTiger/ScoringMathTea and Troy, that give attackers remote access to the infected computer and the ability to steal data.

Read the video transcript

You get a LinkedIn message: a recruiter offering a dream role at Lockheed Martin or Enveil, out of nowhere. This is Lazarus Group’s “Operation Dream Job”: they send a job PDF, then pressure you to install a special viewer called SecurityPDF from sites like envell.xyz or enveil.online. The moment you run that viewer, it quietly drops backdoors like ForestTiger and Troy, giving them remote access to your machine and your company’s data. If any recruiter ever tells you to install a special viewer or tool to open their job PDF, stop and report it to Security, do not install it, no matter how good the offer sounds.

Similar attacks

Fake Job Offers Spread Lazarus Zero-Day Attack

Fake Job Offers Spread Lazarus Zero-Day Attack

Researchers describe a real, ongoing Lazarus-linked campaign where targets are lured with attractive job offers and tricked into downloading a PDF viewer and “job description” documents. Opening the files installs backdoors and, in at least one wave, attackers used a Windows zero-day to gain deep…

August 11, 2026
Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools,…

August 13, 2026
Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a…

August 12, 2026
Lazarus “Dream Job” Lures Spread Zero-Day Attack

Lazarus “Dream Job” Lures Spread Zero-Day Attack

Check Point and Microsoft report North Korea’s Lazarus Group used a long-running “Dream Job” social engineering campaign to target defense-sector job seekers with fake employer sites and trojanized documents/software. Victims were lured into opening malicious PDFs or installing a modified PDF…

August 11, 2026
Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Microsoft says a Russia-linked group compromised hotel and venue Wi‑Fi captive portals to show convincing fake prompts during the normal “connect to Wi‑Fi” flow. The prompts try to trick travelers into installing malware, running commands, or approving a Microsoft sign-in that grants the attacker…

August 4, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026