North Korea-linked Lazarus hackers are targeting employees at European defense companies with convincing recruitment approaches that ultimately deliver malware. The attacks are part of Operation Dream Job, a campaign in which attractive employment opportunities are used to establish contact with selected targets before malicious files are introduced.

 

 

The latest activity has been tracked by Check Point Research since early 2026 and is concentrated on Europe’s defense sector. Aerospace and aviation companies are among the targets, alongside organizations working with military technologies including drones, surveillance sensors and robotics. Check Point Research

Rather than beginning with an obvious malicious message, Lazarus operators pose as recruiters representing recognizable defense companies. Potential victims are contacted through professional networking services such as LinkedIn or directly by email and presented with apparently lucrative employment opportunities. The attackers then move the conversation toward documents supposedly connected to the recruitment process.

Check Point documented multiple ways in which those files can lead to a compromised Windows computer. In one attack chain, the victim receives a collection of files that includes a legitimate PDF viewer, a malicious DLL, and an encrypted payload disguised with a PDF extension. Opening the supplied viewer causes the malicious DLL to load, eventually installing a backdoor on the computer. Meanwhile, an authentic-looking PDF is displayed to make the interaction appear normal.

A separate variation uses a modified PDF reader provided as the application needed to view the supposed job document. The Trojanized program checks opened PDFs for a specific hidden marker. When it encounters the expected marker, it extracts concealed malicious code and loads a backdoor directly into memory.

Once established, the backdoor provides capabilities that include executing commands and retrieving files from the compromised computer. This makes the initial recruitment conversation more than a conventional attempt to steal login credentials: the job offer serves as the delivery mechanism for malware intended to establish persistent access to the target’s system.

Researchers also found a more advanced component in the recent campaign involving CVE-2026-68820, a Windows vulnerability. According to Check Point’s analysis, Lazarus exploited the flaw to execute FudModule, a kernel-mode rootkit associated with the group, with SYSTEM privileges. This gave the attackers a powerful method for operating on an already compromised Windows machine.

The targeting also demonstrates how access to one organization can assist subsequent attacks. Check Point identified at least one case in which the reputation and trusted identity of a compromised European organization were abused as part of attempts to approach additional victims.

Operation Dream Job itself predates this particular wave. The campaign has repeatedly relied on employment-themed social engineering, but Check Point says the activity observed in 2026 combines those established recruitment tactics with updated delivery methods, modular malware, compromised web infrastructure and exploitation of a previously unknown vulnerability.

The current targets are particularly notable because they operate in areas directly connected to European defense capabilities. Check Point’s investigation identified organizations involved with aerospace, aviation and specialized military technology rather than describing the activity as an indiscriminate phishing campaign.

Microsoft lists security vulnerabilities affecting its products through the Microsoft Security Response Center’s Security Update Guide. The latest Operation Dream Job findings, however, come from Check Point’s investigation of the Lazarus campaign and its attacks against European defense-sector targets.

Check Point attributes the activity to Lazarus and says its findings show the group continuing to modify Operation Dream Job rather than abandoning its established recruitment lure. In the attacks documented during 2026, what appears to be a promising defense-industry job opportunity can instead end with a compromised Windows system and a Lazarus backdoor running on the victim’s computer.

Leave a Reply