Lazarus zero-day fools Google in Dream Job wave
New Lazarus campaign abuses Windows zero-day and fake job lures to breach defense firms, fooling Google's filters.
Security researchers say North Korea's Lazarus Group is running a fresh wave of its long-running "Operation Dream Job" campaign, and this time it came armed with a previously undocumented backdoor, a brand new Windows zero-day vulnerability, and a never-before-seen web shell — all wrapped in a convincing job recruitment scam that, at least in some cases, slipped past Google's own defenses.
Fake companies and dreamed-up jobs
Check Point Research says it uncovered the campaign, which is characteristic of Lazarus. The group, a state-sponsored hacking collective on the payroll of the North Korean government, is known for targeting cryptocurrency developers and other professionals in the Web3 industry, stealing their tokens and using the money to fund the country's weapons program and the wider state apparatus.
Operation Dream Job has been going on for years, and it lures victims with highly lucrative but bogus job opportunities. The attackers invent a fake company, often in the software development, defense, aerospace, or military industries, and then create that company's website, LinkedIn account, and fake people supposedly employed there. They reach out to their targets with promises of great working conditions, amazing salaries, and the chance to work on exciting projects.
Interviews that end in compromise
Victims who take the bait are then led through a series of "interviews" and somewhere along the line, they are either given weaponized PDF files or asked to download and run executables and other code as part of a "training exercise" or "skill evaluation." At that moment, the victims get compromised, while the attackers gain access to their actual employers' infrastructure.
From there, the ending can be relatively different. Lazarus has, on at least one occasion, stolen more than a billion dollars in cryptocurrency from one of its victims.
Google's search filters fooled
Perhaps the biggest finding is that Lazarus even managed to fool Google: fake Lockheed Martin and Enveil job postings all made it through filters, while spoofed, malicious websites were showing at the top of search results.
That detail matters because it shows how far the campaign got before being spotted. The group's ability to get malicious pages indexed and ranked is a reminder that job seekers can't count on search engines to filter out scams.
Windows zero-day and the Troy backdoor
There is also the new Windows vulnerability the group has been exploiting. The zero-day, now tracked as CVE-2026-68820, is described as a "use-after-free bug in Windows Ancillary Function Driver for WinSock," allowing authorized attackers to elevate privileges locally.
This bug was found in a core Windows networking component and allows an attacker who already deployed malware on the machine to escalate privileges to the highest level. Microsoft patched it on August 11 2026.
Lazarus used this bug to deploy a previously undocumented backdoor called Troy. This malware comes with 17 commands, including file upload and download, interactive shell access, in-memory DLL injection, and process termination.
RelayShell and compromised webmail
The group was also using compromised Roundcube webmail and CMS servers as C2 relays, instead of simply running their own infrastructure, and they were deploying a new PHP web shell called RelayShell. This one doesn't behave like a conventional backdoor, since it passes commands and responses between victims and operators through text files.
In one of the observed infection chains, Check Point also found the crooks using SecurityPDF, a trojanized PDF viewer which they were hosting on websites impersonating a legitimate business called Enveil. The viewer scans PDF files for a particular hidden marker and, if it finds it, decrypts it and loads Troy directly into memory.
Targets shift to defense and aerospace
Lazarus usually targets cryptocurrency and software developers. This time around, however, it set its sights on defense organizations, aerospace companies, as well as those working in aviation. Most of the victims are located in Europe and India, with confirmed activity in France, Germany, Brazil and India.
Check Point also said that not all victims were also targets — some of the organizations compromised in the attacks were later used as infrastructure. In at least one case, Lazarus compromised a Western European organization and used it to send spear-phishing messages to additional victims, effectively exploiting that organization's reputation and trusted communications.
Why this matters to your workforce
Since these attacks primarily start with a social engineering element, the best course of action is to educate employees on the dangers of phishing and the fact that, if someone is reaching out with a job offer too good to be true — it most likely is.
The campaign's success at fooling Google's filters and using legitimate-looking companies as cover suggests that even savvy professionals can be drawn in. The shift toward defense and aerospace targets also raises the stakes for those industries, where a single compromised employee could expose sensitive projects or supply chain connections. For organizations in any sector, the lesson is to treat unsolicited job offers with suspicion, verify any company independently, and train staff to recognize the signs of a recruitment scam before they click.
Sources
- TechRadar Original source
Continue Reading
Plug and Pwn attacks exploit Windows PnP for SYSTEM
Researchers show fake USB devices can trigger Windows to install vulnerable vendor software, granting SYSTEM privileges.
Fake Hires: The Identity Gap in Onboarding
State and FBI warnings highlight how fake remote workers bypass hiring controls to gain network access.
Stealthy Guest-Access Attacks Hit Salesforce, ServiceNow
Researchers uncover 'City-Forum' campaign using a custom toolset to exploit unauthenticated guest access in Salesforce and ServiceNow.