Lazarus Group Exploits Windows Zero-Day in Fake LinkedIn Recruiter Campaign
North Korea's Lazarus Group has been caught running a new wave of Operation Dream Job, a long-running campaign, according to Check Point Research, that tricks professionals in defence and aerospace into thinking they are being headhunted by companies like Lockheed Martin and Enveil. Targets in France, Germany, Brazil, and India received convincing LinkedIn messages from fake recruiters before being handed malicious files.
The attack runs two parallel infection paths. In the first, victims download what looks like a legitimate PDF viewer called SecurityPDF. When a specially marked document is opened through it, the app quietly loads a backdoor called Troy directly into memory, giving attackers remote access and 17 commands to control the machine. In the second path, victims download an encrypted archive that triggers a DLL side-loading chain (where a legitimate application is tricked into loading a malicious code library instead of a legitimate one). This installs a downloader called MISTPEN, which communicates back to attacker-controlled servers through Microsoft OneDrive before deploying a second backdoor called ForestTiger.
Both paths eventually exploit CVE-2026-68820 (CVSS 7.0, High), a privilege escalation flaw in the Windows Ancillary Function Driver for WinSock. Think of it like a thief who already slipped inside your building using a borrowed keycard, then finds a filing cabinet exploit to print themselves a master key for every room. Once triggered, the attacker jumps from limited access to full SYSTEM-level control of the machine, the kind of control normally reserved for the operating system itself.
What you should do: Apply Microsoft's August 2026 Patch Tuesday updates now. A device restart is required — there is no workaround.
Sources

