Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

This North Korean recruitment scam was so convincing it even fooled Google

Fake sites were popping up at the top of search engine results pages and used to convince victims to download a trojanized PDF viewer.

This North Korean recruitment scam was so convincing it even fooled Google

A new wave of cyber attacks, dubbed "Operation Dream Job," has been uncovered by security experts from Check Point Research. The attacks, attributed to the North Korean hacking collective Lazarus Group, employ a zero-day, previously undocumented Windows vulnerability and a novel webshell/relay. Lazarus Group, known for targeting cryptocurrency developers and professionals in the Web3 industry, has been operating this campaign for years, luring victims with lucrative but false job opportunities.

The scam involves creating fake companies, often in software development, defense, aerospace, or military sectors, and establishing fake websites, LinkedIn accounts, and employee profiles. Attackers then contact targets, offering attractive working conditions, high salaries, and exciting projects. Once victims are enticed, they are led through a series of interviews, during which they may receive weaponized PDF files or be asked to download and run executables, ultimately compromising their employers' infrastructure.

Alarmingly, Lazarus managed to bypass Google's filters, with fake job postings from companies like Lockheed Martin and Enveil appearing at the top of search results. The group exploited a newly discovered Windows zero-day vulnerability (CVE-2026-68820), allowing them to escalate privileges locally. This vulnerability, found in a core Windows networking component, enables attackers who have already deployed malware on a machine to gain the highest level of access.

Lazarus also utilized compromised Roundcube webmail and CMS servers as command and control (C2) relays, deploying a new PHP webshell called RelayShell. This webshell differs from conventional backdoors as it communicates between victims and operators through text files. In an observed infection chain, the group used SecurityPDF, a trojanized PDF viewer hosted on websites impersonating a legitimate business called Enveil.

The viewer scans PDF files for a hidden marker, decrypts the file, and loads the Trojan directly into memory.

While Lazarus typically targets cryptocurrency and software developers, this time, they shifted their focus to defense organizations, aerospace companies, and aviation professionals. Most victims are located in Europe and India, with confirmed activity in France, Germany, Brazil, and India. Additionally, some compromised organizations were later exploited to send spear-phishing messages to additional victims, exploiting their reputation and trusted communications.

To mitigate such attacks, security experts recommend educating employees on the dangers of phishing and emphasizing that job offers too good to be true are likely just scams.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

Intel AMX Performance With The Xeon 678X Workstation CPU

One of the most compelling features for Intel Xeon 6 Granite Rapids alongside MRDIMMs is Advanced Matrix Extensions (AMX) for helping accelerate AI workloads and more.

  • Xeon 678X CPU features AMX for AI workloads
  • AMX implementation in Xeon 678X has no power/thermal penalties
  • Xeon 678X tested with 4x32GB DDR5-6400 memory in HP Z4 G6i

More from Wednesday 12 August →