{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-lazarus-pairs-fake-recruiter-approaches-with-a-windows-zero-day"},"incident":{"slug":"2026-lazarus-pairs-fake-recruiter-approaches-with-a-windows-zero-day","title":"Lazarus pairs fake recruiter approaches with a Windows zero-day","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Defence and aerospace organisations in Western Europe, India and South America","sector":"Defense","country":"Global","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Espionage","Credential Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Lazarus Group (North Korea)","summary":"Check Point found that North Korea's Lazarus Group had been exploiting CVE-2026-68820, a local privilege escalation flaw in the Windows AFD.sys driver, in its Operation Dream Job campaign since at least early July 2026. Microsoft patched the zero-day on 11 August 2026. Targets were defence and aerospace organisations, mainly in Western Europe and India and extending to South America. Successful compromises deployed the FudModule kernel rootkit and a backdoor named Troy.","how_it_worked":"Operators posed as recruiters offering roles at legitimate companies, most plausibly approaching targets through LinkedIn or messaging apps, and steered them into downloading malicious files including a trojanised PDF. The pretext works because a defence engineer receiving a career approach has a legitimate reason to open an attached job description or assessment. Execution then escalated to SYSTEM through the AFD.sys zero-day, installing a kernel-mode rootkit. One compromised French organisation was reused as a launch point for spear-phishing further targets, borrowing its real domain and relationships as the next trust signal.","lessons":"Recruitment documents from unsolicited approaches should be opened only in a sandbox or a browser-based viewer, and application allowlisting stops the downloaded binary before the privilege escalation matters.","confidence":"Confirmed","sources":[{"title":"Lazarus hackers pair fake job offers with Windows zero-day exploit","url":"https://www.helpnetsecurity.com/2026/08/12/north-korea-lazarus-fake-job-offers/","publisher":"Help Net Security"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-lazarus-pairs-fake-recruiter-approaches-with-a-windows-zero-day"}}