Skip to content
NetarxImpact Database
Fake Job Offer / Recruitment LureNo AI reportedConfirmedCampaign

Lazarus pairs fake recruiter approaches with a Windows zero-day

Defence and aerospace organisations in Western Europe, India and South America · Defense · Global · July 2026

What happened

Check Point found that North Korea's Lazarus Group had been exploiting CVE-2026-68820, a local privilege escalation flaw in the Windows AFD.sys driver, in its Operation Dream Job campaign since at least early July 2026. Microsoft patched the zero-day on 11 August 2026. Targets were defence and aerospace organisations, mainly in Western Europe and India and extending to South America. Successful compromises deployed the FudModule kernel rootkit and a backdoor named Troy.

How the deception worked

Operators posed as recruiters offering roles at legitimate companies, most plausibly approaching targets through LinkedIn or messaging apps, and steered them into downloading malicious files including a trojanised PDF. The pretext works because a defence engineer receiving a career approach has a legitimate reason to open an attached job description or assessment. Execution then escalated to SYSTEM through the AFD.sys zero-day, installing a kernel-mode rootkit. One compromised French organisation was reused as a launch point for spear-phishing further targets, borrowing its real domain and relationships as the next trust signal.

The control that would have caught it· our reading, not a claim from the sources

Recruitment documents from unsolicited approaches should be opened only in a sandbox or a browser-based viewer, and application allowlisting stops the downloaded binary before the privilege escalation matters.

Sources (1)

  1. Lazarus hackers pair fake job offers with Windows zero-day exploit
    Help Net Security·helpnetsecurity.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.