Lazarus Hackers Exploit Windows Zero-Day in Fake Job Scam
It typically begins the same way it has for years, with an approach from a recruiter offering a role at a company the target would recognize, accompanied by a PDF describing the position in convincing detail. That approach remains one of the most effective entry points used by state sponsored threat actors today, and Check Point Research has spent recent months tracking a new wave of it. Operation Dream Job, the long running campaign attributed to the North Korea affiliated Lazarus group, has resurfaced with a previously undisclosed Windows vulnerability (CVE-2026-68820), a newly identified backdoor, and a command and control architecture built almost entirely on infrastructure the group does not own.
Key Takeaways
- Check Point Research uncovered a new wave of a long running, state sponsored campaign that uses fake job offers to target the defense sector, with particular focus on aerospace and aviation organizations in Europe and...
Copyright of this story solely belongs to itvoice.in. To see the full text click HERE