< Back to situations

This situation has concluded

It was preserved as a record on September 11; the timeline below shows how it unfolded, with sources. Get the briefing to follow the top situations still developing: three emails a week, sourced and in order.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 12 sources · 1 days · First seen · Last updated

Recruitment-themed cyberespionage campaigns

Overview

Multiple sophisticated cyberespionage campaigns have been identified using social engineering tactics disguised as recruitment processes.

In ‘Operation Dream Job,’ the North Korean-linked Lazarus Group targets defense, aerospace, and aviation professionals in Europe, India, and Brazil. Attackers pose as recruiters on platforms like LinkedIn to distribute malicious files, such as a modified PDF reader. This campaign exploits a Windows zero-day vulnerability, CVE-2026-68820, in the Microsoft AFD.sys driver to gain system-level privileges and deploy malware including the ‘Troy’ modular backdoor.

Simultaneously, a subgroup of the GRU-affiliated Sandworm group, identified as UAC-0145, has been targeting IT professionals and system administrators since at least May 2026. These actors pose as recruiters from ATLAS Business Group conducting screenings for Sopra Steria Bulgaria. After moving communications to Telegram and conducting video interviews, attackers direct victims to download ‘SopraVPN’ from SourceForge. This custom client, a modified version of WireGuard, contains a backdoor designed to execute commands on the victim’s system.

Entities

Sopra Steria Bulgaria · Check Point Research · CERT-UA · Lockheed Martin · Microsoft

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. about 1 month ago

    [TECHNOLOGY] 2 sources
    Sandworm subgroup targets IT professionals via fake job interviews

    Sandworm-linked threat actors are using fake job interviews and fraudulent VPN software to deploy malware targeting IT specialists and system administrators in Ukraine.

  2. about 1 month ago

    [TECHNOLOGY] 10 sources
    Lazarus Group targets defense sector with fake job offers and Windows zero-day

    North Korea-linked Lazarus Group is using fake job offers and a Windows zero-day vulnerability to target defense and aerospace professionals in a campaign called ‘Operation Dream Job’.

Sources

4gnews.pt · aeiou.pt · blogspan.net · borncity.com · dev.to · flagthis.com · infopoint-security.de · it-daily.net · onislam.net · research.checkpoint.com · sempreupdate.com.br · thehackernews.com