A Familiar Scam Gets a Dangerous New Tool
North Korea's state-sponsored Lazarus Group has revived its long-running "Operation Dream Job" campaign, and this time the group has added a serious upgrade: a Windows zero-day vulnerability tracked as CVE-2026-68820. According to reporting from SC Media, the threat actor is using this previously unknown flaw to gain SYSTEM-level access on victim machines before deploying a custom backdoor referred to as Troy. The targets are not random. Researchers say the campaign is focused on defense and aerospace organizations, sectors that hold sensitive intellectual property and information of clear interest to a sanctioned nation-state.
The attack chain starts in a place many job seekers would never suspect: a recruiting email. Initial access is gained through fake job offers, a tactic Lazarus has used for years to lure engineers and analysts into opening malicious files. In this latest wave, victims are also tricked into downloading what appears to be a legitimate PDF viewer, which instead delivers the malware needed to exploit the Windows zero-day.
How the Campaign Actually Works
What makes this operation notable is not just the social engineering, which is well-documented Lazarus tradecraft, but the technical escalation behind it. A zero-day is a vulnerability that vendors have not yet patched, meaning defenders have no advance warning and no fix available at the time of exploitation. By pairing a fake job offer with a booby-trapped PDF viewer, Lazarus creates a scenario where a target's normal, everyday actions, opening an attachment, installing a document reader, become the entry point for a privilege escalation exploit.
Once the zero-day is triggered, the attackers reportedly achieve SYSTEM-level privileges, the highest level of access on a Windows machine. That level of control allows the Troy backdoor to operate with minimal restrictions, potentially enabling data exfiltration, persistent surveillance, and lateral movement across a network. For an organization in the defense or aerospace industry, that kind of access could expose proprietary research, personnel records, or communications that have national security implications well beyond a typical corporate breach.
Why This Matters Beyond the Defense Sector
It is easy to read a story like this and assume it only concerns large contractors with classified clearances. But the mechanics of the attack, fake recruiting outreach paired with a trojanized software download, are broadly applicable. Lazarus Group has a long history of targeting individuals rather than just institutions, using LinkedIn messages, email, and even messaging apps to build rapport before delivering malware. The same playbook that compromises a defense engineer today could just as easily target a cybersecurity researcher, a journalist, or a cryptocurrency developer tomorrow.
It is also worth remembering where this activity originates. Lazarus Group operates out of North Korea, one of the most tightly controlled information environments in the world, where the regime restricts ordinary citizens' internet access while state-linked units conduct sophisticated global operations. For readers curious about how digital access and surveillance work inside North Korea itself, our breakdown of the best VPN for North Korea explains why even basic privacy tools carry enormous risk and consequence in that specific context.
What This Means For You
If you work in defense, aerospace, or any field that regularly receives unsolicited recruiting messages, this campaign is a reminder to treat unexpected job offers with caution, especially ones that ask you to download software to "view" an attachment or complete an assessment. Legitimate recruiters rarely require a special PDF viewer or unusual application to review a resume or job description.
For everyone else, the broader lesson is about patching discipline and email skepticism. Zero-days eventually get fixed once vendors are aware of them, but that only protects you if you actually install updates promptly once a patch becomes available. Until then, the best defense is avoiding the initial infection vector altogether: unsolicited attachments, unfamiliar download links, and job offers that arrive out of nowhere and push urgency.
Actionable Takeaways
Treat unsolicited job offers with skepticism, particularly those requesting software downloads before an interview even happens. Keep Windows and all applications, especially PDF readers, updated as soon as patches are released. Use endpoint detection tools where available, since privilege escalation attempts often leave detectable traces even when the initial exploit is unknown. Organizations in defense-adjacent industries should brief employees specifically on Operation Dream Job tactics, since awareness remains one of the most effective defenses against socially engineered attacks. Staying informed about campaigns like this one is a practical step toward protecting both your organization and your own digital footprint.




