North Korean Hackers Use Fake LinkedIn Job Offers to Breach Security Systems
Cybersecurity researchers at Check Point have uncovered a new cyberattack campaign by the North Korean-linked hacker group Lazarus, targeting defense, aerospace, and security organizations. The campaign, dubbed Operation Dream Job, uses fake job offers sent via LinkedIn and messaging apps to trick employees into opening malicious files or installing malware. Victims receive seemingly legitimate job descriptions from well-known companies, but the attached files contain software that enables attackers to infiltrate their computers.
The attackers exploited a previously unknown Windows zero-day vulnerability (CVE-2026-68820) that allows privilege escalation after malware execution, granting them system-level control. Check Point reported the flaw to Microsoft on July 28, 2026; Microsoft confirmed it and released a patch on August 11, 2026. The malware, named Troy, functions as a backdoor with 17 commands, including file search, upload/download, process termination, and remote code execution.
Lazarus also used compromised legitimate infrastructure such as hacked websites, webmail servers, and CMS platforms to relay commands, making detection difficult. Some servers were breached using leaked credentials or unpatched vulnerabilities, and attackers even leveraged already compromised organizations to send phishing messages to new victims, exploiting their reputation.
Check Point emphasized the sophistication of the campaign, noting that the attackers combined legitimate branding, high search rankings, and trusted infrastructure to mask their operations. They advised organizations to immediately apply security updates, verify software sources, monitor network traffic for anomalies, and adopt a zero-trust approach even toward seemingly trustworthy sites and partners.
Lazarus is known for long-term espionage and financially motivated attacks, often impersonating recruiters to target sensitive industries. This campaign highlights the evolving complexity of cyber threats where trust can be forged and weaponized to breach critical systems.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.