Compare full coverage across 2 outlets
Security17:30 · 16h ago

North Korean Hackers Use Fake LinkedIn Job Offers to Breach Security Systems

MakoCenter
Translated & summarized from Mako by baba
The story · English

Cybersecurity researchers at Check Point have uncovered a new cyberattack campaign, dubbed Operation Dream Job, conducted by the Lazarus Group, a hacking collective linked to North Korea. The campaign targets defense, aerospace, and security organizations by sending fake job offers through LinkedIn and messaging apps. These offers appear legitimate, often including authentic company branding and realistic job descriptions, but contain malicious software designed to infiltrate victims' computers.

The attackers exploit a previously unknown Windows zero-day vulnerability (CVE-2026-68820) that elevates their access privileges once malware is executed. This vulnerability allows attackers to gain system-level control, even on fully updated Windows 11 machines. Check Point reported the flaw to Microsoft on July 28, 2026; Microsoft confirmed it shortly after and released a security patch on August 11, 2026.

The malware, named Troy, functions as a backdoor enabling remote control with capabilities such as file searching, uploading, downloading, archiving, command execution, and memory-resident code running. Lazarus also cleverly uses compromised legitimate infrastructure, including hacked websites, webmail servers, and CMS platforms, to relay commands and mask their activities. In some cases, they exploited previously breached organizations to send phishing messages, leveraging their reputation to increase trustworthiness.

Check Point emphasizes the sophistication of the campaign, noting that traditional phishing detection methods are insufficient because the attackers use trusted sites and genuine-looking files. They advise organizations to promptly apply security updates, verify software sources, monitor for unusual network activity, and adopt a zero-trust approach even with seemingly reliable partners and websites.

Lazarus Group is known for prolonged espionage and financially motivated attacks against governments and sensitive industries. This campaign highlights their continued use of fake recruitment tactics to compromise high-value targets.

Read the original at Mako
Full coverage · 2 outlets
100% centerFirst: Mako · 16h ago

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Center 2
Related stories · 5

Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.

Open the live terminal