{
  "id": 680898,
  "title": "This North Korean recruitment scam was so convincing it even fooled Google",
  "url": "https://urgent.news/2026/08/12/this-north-korean-recruitment-scam-was-so-convincing-it-even-fooled",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-12T17:05:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/this-north-korean-recruitment-scam-was-so-convincing-it-even-fooled-google"
  },
  "original_language": "en",
  "account": "A new wave of cyber attacks, dubbed \"Operation Dream Job,\" has been uncovered by security experts from Check Point Research. The attacks, attributed to the North Korean hacking collective Lazarus Group, employ a zero-day, previously undocumented Windows vulnerability and a novel webshell/relay. Lazarus Group, known for targeting cryptocurrency developers and professionals in the Web3 industry, has been operating this campaign for years, luring victims with lucrative but false job opportunities.\n\nThe scam involves creating fake companies, often in software development, defense, aerospace, or military sectors, and establishing fake websites, LinkedIn accounts, and employee profiles. Attackers then contact targets, offering attractive working conditions, high salaries, and exciting projects. Once victims are enticed, they are led through a series of interviews, during which they may receive weaponized PDF files or be asked to download and run executables, ultimately compromising their employers' infrastructure.\n\nAlarmingly, Lazarus managed to bypass Google's filters, with fake job postings from companies like Lockheed Martin and Enveil appearing at the top of search results. The group exploited a newly discovered Windows zero-day vulnerability (CVE-2026-68820), allowing them to escalate privileges locally. This vulnerability, found in a core Windows networking component, enables attackers who have already deployed malware on a machine to gain the highest level of access.\n\nLazarus also utilized compromised Roundcube webmail and CMS servers as command and control (C2) relays, deploying a new PHP webshell called RelayShell. This webshell differs from conventional backdoors as it communicates between victims and operators through text files. In an observed infection chain, the group used SecurityPDF, a trojanized PDF viewer hosted on websites impersonating a legitimate business called Enveil. The viewer scans PDF files for a hidden marker, decrypts the file, and loads the Trojan directly into memory.\n\nWhile Lazarus typically targets cryptocurrency and software developers, this time, they shifted their focus to defense organizations, aerospace companies, and aviation professionals. Most victims are located in Europe and India, with confirmed activity in France, Germany, Brazil, and India. Additionally, some compromised organizations were later exploited to send spear-phishing messages to additional victims, exploiting their reputation and trusted communications.\n\nTo mitigate such attacks, security experts recommend educating employees on the dangers of phishing and emphasizing that job offers too good to be true are likely just scams.",
  "summary": "Fake sites were popping up at the top of search engine results pages and used to convince victims to download a trojanized PDF viewer.",
  "key_points": [
    "North Korean hacking group Lazarus Group launches Operation Dream Job",
    "Targets defense, aerospace, and military sectors with fake job offers",
    "Exploits zero-day Windows vulnerability to gain highest level access"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}