How the Lazarus Group Exploits Job Postings to Infiltrate Organizations

Researchers from Check Point Research have identified a new episode of the “Dream Job” operation, a broad espionage campaign attributed to the North Korean group Lazarus.

This time, the cyberattackers fused highly crafted social engineering with the exploitation of a previously unknown vulnerability to breach the networks of defense and aerospace companies across Europe, India, and South America.

The modus operandi rests on fake job postings that appear to originate from prominent industry names, notably Lockheed Martin and the data security firm Enveil.

To make the ruse credible, the attackers went so far as to create multiple counterfeit sites imitating Enveil, some of which were sufficiently well indexed to appear at the top of search results.

Read also: Handala Hack, an Iranian hacktivist group with destructive methods

Victims, believing they were downloading documents or software from legitimate sources found via a search engine, actually installed the attackers’ malicious program. This approach undermines people’s usual vigilance, since neither the recruiter nor the site nor the Google ranking could reveal the deception.

A precise geopolitical target

Once the trap was sprung, a fake PDF reader named “SecurityPDF” served as the entry point to quietly deploy a new modular backdoor, nicknamed “Troy,” capable of executing seventeen different commands according to operators’ instructions.

Meanwhile, the attackers deployed an updated version of the FudModule rootkit (3.1), which exploited a previously unknown vulnerability in the Windows AFD.sys driver to obtain the highest system privileges and disable detection tools typically deployed by enterprises.

This vulnerability, CVE-2026-68820, was reported to Microsoft, which fixed it as part of their August 11, 2026, monthly security update.

The sectors targeted include surveillance sensors, drones, and military robotics. Several countries are affected, including France, Germany, Brazil, and India. India is particularly exposed due to the rapid growth of its defense and aerospace industry.

A discreet command-and-control infrastructure

Rather than relying on easily detectable dedicated servers, Lazarus favored hijacking Roundcube webmail installations and compromised content management platforms, leveraging a known flaw (CVE-2025-49113, for which a patch already exists) and credentials stolen on the dark web.

Read also: Firewalls: hybridization still a distant horizon?

A new webshell named “RelayShell” enabled the transformation of at least seventeen compromised servers into relays for communications between infected machines and the group’s operators.

What researchers find particularly troubling is that a French organization, already compromised, was subsequently used as a launching pad to trigger fresh waves of targeted phishing around the world, leveraging its reputation to lend credibility to the new trap messages. A successful intrusion can thus become a springboard for further attacks, well beyond the initial victim.

For Sergey Shykevich, threat intelligence leader at Check Point Software, the most alarming aspect of this campaign is not so much the zero-day vulnerability exploited but the attackers’ ability to rely on signals of trust that are typically dependable: strong search result rankings, the appearance of familiar brands, or the reputation of organizations already breached.

Dawn Liphardt

Dawn Liphardt

I'm Dawn Liphardt, the founder and lead writer of this publication. With a background in philosophy and a deep interest in the social impact of technology, I started this platform to explore how innovation shapes — and sometimes disrupts — the world we live in. My work focuses on critical, human-centered storytelling at the frontier of artificial intelligence and emerging tech.