This situation has concluded
It was preserved as a record on September 11; the timeline below shows how it unfolded, with sources. Get the briefing to follow the top situations still developing: three emails a week, sourced and in order.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 12 sources · 1 days · First seen · Last updated
Recruitment-themed cyberespionage campaigns
Overview
Multiple sophisticated cyberespionage campaigns have been identified using social engineering tactics disguised as recruitment processes.
In ‘Operation Dream Job,’ the North Korean-linked Lazarus Group targets defense, aerospace, and aviation professionals in Europe, India, and Brazil. Attackers pose as recruiters on platforms like LinkedIn to distribute malicious files, such as a modified PDF reader. This campaign exploits a Windows zero-day vulnerability, CVE-2026-68820, in the Microsoft AFD.sys driver to gain system-level privileges and deploy malware including the ‘Troy’ modular backdoor.
Simultaneously, a subgroup of the GRU-affiliated Sandworm group, identified as UAC-0145, has been targeting IT professionals and system administrators since at least May 2026. These actors pose as recruiters from ATLAS Business Group conducting screenings for Sopra Steria Bulgaria. After moving communications to Telegram and conducting video interviews, attackers direct victims to download ‘SopraVPN’ from SourceForge. This custom client, a modified version of WireGuard, contains a backdoor designed to execute commands on the victim’s system.
Entities
Sopra Steria Bulgaria · Check Point Research · CERT-UA · Lockheed Martin · Microsoft
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 9 SOURCES] The Lazarus Group is conducting a cyberespionage campaign called ‘Operation Dream Job’ targeting the defense, aerospace, and aviation sectors.
- [● 7 SOURCES] The attackers exploited a Windows zero-day vulnerability, tracked as CVE-2026-68820, in the Microsoft AFD.sys driver.
- [● 7 SOURCES] The campaign targets professionals in Europe, India, Brazil, and other regions.
- [● 4 SOURCES] Victims are lured into downloading a modified PDF reader called ‘SecurityPDF’ to view fraudulent job descriptions.
- [● 3 SOURCES] The attackers use a malware component called MISTPEN to collect system information and execute tasks via Microsoft Graph and OneDrive.
- [● 3 SOURCES] Attackers used fake job postings that impersonated companies such as Lockheed Martin and Enveil.
- [● 2 SOURCES] The campaign utilizes a modular backdoor named ‘Troy’ that features 17 different commands for system control.
- [○ 1 SOURCE] Microsoft released a patch for the CVE-2026-68820 vulnerability on August 11, 2026.
Timeline
-
about 1 month ago
[TECHNOLOGY] 2 sourcesSandworm subgroup targets IT professionals via fake job interviewsSandworm-linked threat actors are using fake job interviews and fraudulent VPN software to deploy malware targeting IT specialists and system administrators in Ukraine.
-
about 1 month ago
[TECHNOLOGY] 10 sourcesLazarus Group targets defense sector with fake job offers and Windows zero-dayNorth Korea-linked Lazarus Group is using fake job offers and a Windows zero-day vulnerability to target defense and aerospace professionals in a campaign called ‘Operation Dream Job’.
Sources
4gnews.pt · aeiou.pt · blogspan.net · borncity.com · dev.to · flagthis.com · infopoint-security.de · it-daily.net · onislam.net · research.checkpoint.com · sempreupdate.com.br · thehackernews.com