# Recruitment-themed cyberespionage campaigns

> Live situation record from CLSTR: https://clstr.news/situations/recruitment-themed-cyberespionage-campaigns
> Updated: 2026-08-11T18:36:47.000Z. Sources: 12. Developments: 2.

Multiple sophisticated cyberespionage campaigns have been identified using social engineering tactics disguised as recruitment processes.

In ‘Operation Dream Job,’ the North Korean-linked Lazarus Group targets defense, aerospace, and aviation professionals in Europe, India, and Brazil. Attackers pose as recruiters on platforms like LinkedIn to distribute malicious files, such as a modified PDF reader. This campaign exploits a Windows zero-day vulnerability, CVE-2026-68820, in the Microsoft AFD.sys driver to gain system-level privileges and deploy malware including the ‘Troy’ modular backdoor.

Simultaneously, a subgroup of the GRU-affiliated Sandworm group, identified as UAC-0145, has been targeting IT professionals and system administrators since at least May 2026. These actors pose as recruiters from ATLAS Business Group conducting screenings for Sopra Steria Bulgaria. After moving communications to Telegram and conducting video interviews, attackers direct victims to download ‘SopraVPN’ from SourceForge. This custom client, a modified version of WireGuard, contains a backdoor designed to execute commands on the victim’s system.

## Claims

- The Lazarus Group is conducting a cyberespionage campaign called ‘Operation Dream Job’ targeting the defense, aerospace, and aviation sectors. (corroborated by 9 sources)
- The attackers exploited a Windows zero-day vulnerability, tracked as CVE-2026-68820, in the Microsoft AFD.sys driver. (corroborated by 7 sources)
- The campaign targets professionals in Europe, India, Brazil, and other regions. (corroborated by 7 sources)
- Victims are lured into downloading a modified PDF reader called ‘SecurityPDF’ to view fraudulent job descriptions. (corroborated by 4 sources)
- The attackers use a malware component called MISTPEN to collect system information and execute tasks via Microsoft Graph and OneDrive. (corroborated by 3 sources)
- Attackers used fake job postings that impersonated companies such as Lockheed Martin and Enveil. (corroborated by 3 sources)
- The campaign utilizes a modular backdoor named ‘Troy’ that features 17 different commands for system control. (corroborated by 2 sources)
- Microsoft released a patch for the CVE-2026-68820 vulnerability on August 11, 2026. (single source)

## Timeline

### 2026-08-11: Sandworm subgroup targets IT professionals via fake job interviews

Sandworm-linked threat actors are using fake job interviews and fraudulent VPN software to deploy malware targeting IT specialists and system administrators in Ukraine.

2 sources. https://clstr.news/cluster/sandworm-subgroup-targets-it-professionals-via-fake-job-interviews

### 2026-08-11: Lazarus Group targets defense sector with fake job offers and Windows zero-day

North Korea-linked Lazarus Group is using fake job offers and a Windows zero-day vulnerability to target defense and aerospace professionals in a campaign called ‘Operation Dream Job’.

10 sources. https://clstr.news/cluster/lazarus-group-targets-defense-sector-with-zero-day-attacks

---
Cite as: Recruitment-themed cyberespionage campaigns. CLSTR, https://clstr.news/situations/recruitment-themed-cyberespionage-campaigns
