This North Korean recruitment scam was so convincing it even fooled Google
Fake sites were popping up at the top of search engine results pages and used to convince victims to download a trojanized PDF viewer.
A new wave of cyber attacks, dubbed "Operation Dream Job," has been uncovered by security experts from Check Point Research. The attacks, attributed to the North Korean hacking collective Lazarus Group, employ a zero-day, previously undocumented Windows vulnerability and a novel webshell/relay. Lazarus Group, known for targeting cryptocurrency developers and professionals in the Web3 industry, has been operating this campaign for years, luring victims with lucrative but false job opportunities.
The scam involves creating fake companies, often in software development, defense, aerospace, or military sectors, and establishing fake websites, LinkedIn accounts, and employee profiles. Attackers then contact targets, offering attractive working conditions, high salaries, and exciting projects. Once victims are enticed, they are led through a series of interviews, during which they may receive weaponized PDF files or be asked to download and run executables, ultimately compromising their employers' infrastructure.
Alarmingly, Lazarus managed to bypass Google's filters, with fake job postings from companies like Lockheed Martin and Enveil appearing at the top of search results. The group exploited a newly discovered Windows zero-day vulnerability (CVE-2026-68820), allowing them to escalate privileges locally. This vulnerability, found in a core Windows networking component, enables attackers who have already deployed malware on a machine to gain the highest level of access.
Lazarus also utilized compromised Roundcube webmail and CMS servers as command and control (C2) relays, deploying a new PHP webshell called RelayShell. This webshell differs from conventional backdoors as it communicates between victims and operators through text files. In an observed infection chain, the group used SecurityPDF, a trojanized PDF viewer hosted on websites impersonating a legitimate business called Enveil.
The viewer scans PDF files for a hidden marker, decrypts the file, and loads the Trojan directly into memory.
While Lazarus typically targets cryptocurrency and software developers, this time, they shifted their focus to defense organizations, aerospace companies, and aviation professionals. Most victims are located in Europe and India, with confirmed activity in France, Germany, Brazil, and India. Additionally, some compromised organizations were later exploited to send spear-phishing messages to additional victims, exploiting their reputation and trusted communications.
To mitigate such attacks, security experts recommend educating employees on the dangers of phishing and emphasizing that job offers too good to be true are likely just scams.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.