Received a job offer on LinkedIn? You might be getting hacked
Check Point researchers have uncovered a campaign by the Lazarus hacker group against defense, aviation, and aerospace organizations, which exploited a Zero Day vulnerability in Windows and hid behind trusted websites. The victim receives a job offer at a well-known company and a job description that looks legitimate, but behind the file hides software that allows attackers to penetrate the computer.

Check Point researchers have uncovered a new wave of cyberattacks attributed to the Lazarus hacker group, which is associated with North Korea. According to Check Point, the campaign, Operation Dream Job, uses fake job offers to lure employees in defense, aviation, and aerospace organizations into opening files or installing malware.
"What makes this campaign particularly dangerous is not only the use of a Zero Day vulnerability, but also the way Lazarus integrated legitimate and reliable infrastructure at almost every stage of the attack," says Sergey Shukevich, a director in Check Point's research department. The attackers hid in plain sight, behind search results that rank high, branding of real companies, and the reputation of organizations they had already managed to hack.
The attack usually begins with an approach that looks like a message from a real recruiter, sometimes via LinkedIn or messaging apps. The victim receives a job offer at a well-known company and a job description that looks legitimate, but behind the file hides software that allows attackers to penetrate the computer. The researchers identified activity against defense, aviation, and aerospace organizations.
According to the research, in one of the methods of operation, a file was sent to the victim including a legitimate and digitally signed PDF program, but with malicious components alongside it. When the user opens the program, they see a job description that looks real, and at the same time, malware is activated on the computer. In one of the examples revealed, the document posed as a job description for the Lockheed Martin corporation.
In another path, victims were directed to download a PDF program called SecurityPDF from sites that posed as the American technology company Enveil, which, according to Check Point, has no connection to the attack. The software looked like a regular document viewing program, but in practice, it was modified by the attackers and was capable of running malicious code from PDF documents specifically prepared for the attack. From the moment the malware is activated, it begins to collect information about the computer and prepare the ground for the next stages.
During the research, Check Point researchers discovered that the attackers also exploited a previously unknown vulnerability in Windows, which received the designation CVE-2026-68820. This is a privilege escalation vulnerability: it does not allow an attacker to enter the computer in the first place, but after they have already managed to run malware on it, it allows them to move from limited access to the highest privileges in the system. In simple words, after the victim activated the malicious file, the vulnerability allowed the attackers to gain control at a level usually reserved for the operating system itself.
At Check Point, they say that initially they thought it was a version of a previous vulnerability that had already been fixed by Microsoft, but tests on a fully updated Windows 11 computer showed that the attack still succeeds — and clarified that it is a new vulnerability. According to the company, it reported the vulnerability to Microsoft on July 28, 2026; Microsoft confirmed the finding three days later, assigned the vulnerability the number CVE-2026-68820 on August 5, and on August 11 published a fix for it as part of the Patch Tuesday updates.
Alongside the Windows vulnerability, the researchers also revealed in the campaign a new malware that had not been documented before, which received the name Troy. This is a backdoor that allows the attack operators to remotely control the hacked computer and perform a variety of actions. The researchers identified 17 different commands in it, including searching for files, uploading and downloading them, creating archives for the purpose of extracting information from the computer, running commands, terminating processes, and running additional code directly from memory.
One of the unusual findings in the research concerns the infrastructure that the attackers use to control hacked computers. Instead of setting up their own servers, Lazarus used to a large extent the infrastructure of other organizations: legitimate websites, Webmail servers, and CMS systems that were hacked and turned into relay stations for transferring commands between the attackers and the victims. Some of the servers were hacked using known security vulnerabilities that were not fixed, and in other cases, they used access credentials that had previously leaked to the dark web.
The researchers identified at least 17 different servers that were used as part of this relay network. In at least one case, the attackers used an organization that had already been hacked to send phishing messages to additional victims, while exploiting its name and reputation to make the approach more reliable. Thus, a Webmail server or a corporate site that was not updated, together with a password or access credentials that had already leaked, can turn an organization without its knowledge into part of the attack infrastructure — and from there be used to attack other organizations.
Lazarus is one of the attack groups most identified with North Korea, and has been operating for years against governments, companies, and bodies in the fields of defense, technology, and finance. According to Check Point, the group is known for prolonged campaigns of espionage and data theft, alongside attacks whose goal is also financial profit. One of the methods identified with it is posing as recruiters and sending fake job offers to employees in sensitive industries — the technique that also stands at the center of Operation Dream Job.
"When the site, the file to download, and even the recruiter all look reliable, the old advice of 'looking for the suspicious phishing link' is no longer enough," said Shukevich. The meaning today is that one must take into account that even trust can be faked: install security updates immediately upon their publication, download and verify software through official channels and not rely on their rating in search results, and apply a Zero Trust concept even to sites and partners that look legitimate and with whom we communicate every day.
At Check Point, they recommend that organizations update Windows following the discovered vulnerability, check systems exposed to the internet, ensure they are updated, monitor leaked corporate access credentials, and examine anomalies in traffic even when it comes from infrastructure that looks legitimate.





