Lazarus Uses Fake Jobs to Drop Zero-Day Malware

Help Net Security · High sophistication
Last updated August 12, 2026

Researchers say the North Korea-linked Lazarus group ran “Operation Dream Job,” posing as recruiters and sending fake job offers to lure targets into downloading trojanized PDF tools and opening booby-trapped PDFs. The campaign focused largely on defense-related organizations and used both a Windows zero-day and fake company websites to deliver malware and gain deep control of victims’ systems.

Key findings

  • Lazarus ran “Operation Dream Job,” posing as recruiters and luring victims with job opportunities at well-known companies (e.g., a decoy document with a Lockheed Martin job description).
  • Victims were directed to download malicious files, including an encrypted ZIP containing a legitimate PDF viewer, a malicious DLL (DLL sideloading), and an encrypted payload disguised as a PDF.
  • A second chain used fraudulent job offers impersonating Enveil and instructed targets to download “SecurityPDF,” a trojanized PDF viewer; opening an attacker-prepared PDF triggered payload execution and installed the “Troy” backdoor.
  • Attackers exploited a Windows local privilege escalation zero-day (CVE-2026-68820) to gain SYSTEM privileges; Microsoft patched it on August 11, 2026.
  • Lazarus compromised Roundcube webmail and other servers to relay command-and-control traffic, including deploying a PHP web shell called “RelayShell.”
  • In at least one case, a compromised organization in France was used to send spear-phishing messages to additional targets.

Who’s being targeted

  • Commonly targeted roles: Defense sector staff, Engineering, IT / System administrators, Security operations, HR / Talent acquisition, Executive leadership.
  • Affected industries: Defense sector, Government, IT (system administrators/IT professionals).
  • Attack channels: linkedin, email.
  • Impersonated: Recruiter (job opportunity at well-known companies, e.g., Lockheed Martin), Enveil (impersonated by attackers).

Awareness takeaways

  • Treat unsolicited recruiter/job outreach as untrusted until independently verified via official company channels.
  • Do not install “special” viewers or tools to open a document from a job offer; use approved software and report the message to security.
  • Watch for brand impersonation and lookalike websites in hiring-related communications; check the exact domain before downloading anything.
  • Defense-sector and IT staff should be specifically briefed that job-offer phishing can be used for high-impact espionage, not just credential theft.

Red flags to watch for

  • Unsolicited recruiter outreach with urgent push to open/download files
  • Job documents delivered as encrypted archives or unusual file formats
  • Recruiter cannot be verified through official company channels
  • Job offer instructs you to install a specific “viewer” from a website rather than using standard tools
  • Vendor website looks real but is not the official domain (lookalike site)
  • A PDF that requires a special viewer to open is unusual and risky
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a LinkedIn message: “Hi, I’m recruiting for Lockheed Martin, saw your profile…” Sounds flattering, right? This is Lazarus’ “Operation Dream Job.” They pose as recruiters, send a Lockheed Martin job description, then push you to download an encrypted ZIP with a PDF viewer and a “job details” PDF. In another chain, fake Enveil job offers tell you to install a special PDF tool called “SecurityPDF” from a lookalike website, then open their attached PDF. One click, and the Troy backdoor plus a Windows zero‑day give them SYSTEM‑level access. Here’s the move: if any job offer tells you to download a special viewer or tool to open their PDF, stop and forward it to Security, do not install it, no matter how good the job sounds.

Similar attacks

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Fake Lockheed Jobs Used to Deliver Lazarus Zero-Day

Check Point says North Korea’s Lazarus Group targeted defense and aerospace professionals using convincing fake job offers that led victims to download trojanized PDF software. The campaign used a Windows zero-day (now patched as CVE-2026-68820) to gain full control and hide from security tools,…

August 13, 2026
Fake Job Offers Spread Lazarus Zero-Day Attack

Fake Job Offers Spread Lazarus Zero-Day Attack

Researchers describe a real, ongoing Lazarus-linked campaign where targets are lured with attractive job offers and tricked into downloading a PDF viewer and “job description” documents. Opening the files installs backdoors and, in at least one wave, attackers used a Windows zero-day to gain deep…

August 11, 2026
Lazarus “Dream Job” Lures Spread Zero-Day Attack

Lazarus “Dream Job” Lures Spread Zero-Day Attack

Check Point and Microsoft report North Korea’s Lazarus Group used a long-running “Dream Job” social engineering campaign to target defense-sector job seekers with fake employer sites and trojanized documents/software. Victims were lured into opening malicious PDFs or installing a modified PDF…

August 11, 2026
Fake Recruiters Target Job Seekers With Malicious PDFs

Fake Recruiters Target Job Seekers With Malicious PDFs

North Korea-linked Lazarus Group ran a “Dream Job” campaign targeting people applying for defense and aerospace jobs by posing as recruiters on LinkedIn and other platforms. Victims were sent malicious PDF files; opening them enabled a backdoor and then an exploit for a Windows zero-day…

August 12, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026
Fake Screenshot ZIP Led to DigiCert Cert Theft

Fake Screenshot ZIP Led to DigiCert Cert Theft

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a customer support chat. The attackers then abused DigiCert’s support portal features to intercept EV code-signing certificate “initialization…

July 17, 2026