A Familiar Lure With a Dangerous New Twist
Job scams and recruiter phishing are nothing new, but the latest wave of Operation Dream Job shows how far attackers are willing to go to make a fake opportunity feel real. According to Check Point Research, since early 2026 threat actors linked to the long-running Operation Dream Job campaign have been targeting the defense sector worldwide, with a particular focus on companies in the aerospace and aviation industries. The campaign has previously been tied to North Korea-linked Lazarus Group activity, and this latest wave reportedly pairs recruiter-themed lures with a Windows zero-day exploit, a combination that raises the stakes considerably for anyone in a defense-adjacent role who receives an unsolicited job pitch.
What makes this campaign notable is not just the sector it targets but the sophistication behind it. Rather than relying purely on convincing someone to hand over credentials, the attackers reportedly used a previously unknown software vulnerability to gain deeper access once a target engaged with the lure. That shift, from social engineering alone to social engineering paired with a zero-day, is part of a broader pattern researchers have flagged repeatedly this year, including in the Check Point zero-day coverage from earlier this week, where old and new vulnerabilities alike continue to resurface as attack vectors.
How the Attack Unfolds
Based on the reporting, the attack chain follows a pattern security researchers classify under recognizable techniques: initial access through spear-phishing attachments, and execution that relies on a user opening or interacting with a malicious file. In practice, this typically means a target receives a message that looks like a legitimate recruiter outreach, often referencing a real company or role, complete with an attachment framed as a job description, application form, or assessment task. Once opened, the file triggers code execution on the victim's machine, at which point the zero-day component allows the attackers to bypass protections that would normally catch more conventional malware.
One detail from the research stands out: in at least one case, attackers used a compromised organization in Western Europe to launch further spear-phishing emails, effectively turning a victim's own trusted identity into a launchpad for additional attacks. This is a meaningful escalation. It means the phishing email a target receives might not come from an obviously suspicious address; it could come from a real, previously legitimate contact whose systems have already been compromised. That tactic mirrors a broader trend across recent zero-day incidents, similar in spirit to how attackers exploiting the Cisco FMC zero-day have leaned on active exploitation of trusted infrastructure to expand their reach before detection catches up.
Why Defense and Aerospace Are in the Crosshairs
The targeting pattern here is not random. Defense contractors and aerospace companies sit on valuable intellectual property, government contract information, and supply chain access that make them attractive targets for state-linked espionage operations. Job-themed lures work particularly well against this sector because defense and aerospace firms are constantly recruiting specialized engineers, analysts, and technical staff, many of whom are active on professional networking platforms and open to inbound recruiter contact. That normal hiring behavior becomes the exact vulnerability attackers exploit.
The use of a zero-day also suggests a well-resourced operation. Zero-day vulnerabilities are expensive to discover or acquire and are typically reserved for high-value targets rather than opportunistic, broad-based scams. Their appearance here reinforces that this wave of Operation Dream Job is a targeted espionage effort rather than generic cybercrime.
What This Means For You
If you work in defense, aerospace, aviation, or an adjacent field, this campaign is a reminder that not every unusual recruiter message is harmless, even when it appears to come from a familiar contact or organization. The compromise of a legitimate Western European organization to send follow-on phishing emails shows that trust signals alone (a known sender, a real company name, a professional tone) are no longer reliable indicators of safety.
On a personal level, this is also a privacy story. Once attackers gain a foothold through a zero-day, they can potentially access far more than just work files, including personal communications, credentials, and browsing activity on a compromised device. Anyone handling sensitive professional information should treat unexpected attachments, even well-crafted ones, with heightened scrutiny, and organizations should ensure endpoint protections and patching processes are not solely reliant on catching known threats.
Actionable Takeaways
Be skeptical of unsolicited recruiter outreach that asks you to open attachments or click links, especially if it arrives outside your normal job platform. Verify recruiter identities independently before engaging further. Keep operating systems and security software updated, since zero-day protections often depend on layered defenses rather than a single patch. If you work in a targeted sector, report suspicious job offers to your organization's security team rather than handling them independently. Operation Dream Job's latest wave underscores that even routine professional interactions can become an entry point for sophisticated, targeted attacks, and staying cautious is still one of the most effective defenses available.




