North Korean hackers target European defense companies
Lazarus turns dream jobs into zero-day traps.

Image by Cybernews.
- Lazarus, a DPRK-linked hacking group, is targeting European defense, aerospace, and aviation companies with fake job offers.
- The campaign, called Operation Dream Job, lures victims via LinkedIn or email using fake recruiter messages.
- Attackers exploit Windows zero-day CVE-2026-68820 to deploy the FudModule rootkit with full SYSTEM-level device control.
- Check Point has tracked this Operation Dream Job wave since early 2026, focused on military technology firms.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
European defense companies have recently become the target of sophisticated cyberattacks carried out by Lazarus, a hacking group linked to the Democratic People’s Republic of Korea (DPRK).
The attacks are part of a long-running campaign called Operation Dream Job.
This is how it works.
The campaign starts with a spear-phishing attack, offering someone a lucrative and attractive job opportunity at a well-known company in the defense industry.
In most cases, targets are approached through professional networking platforms such as LinkedIn or directly via email.
Posing as recruiters, the attackers present enticing job opportunities and tempt their target to download malicious files, including a legitimate PDF viewer, a malicious DLL, and an encrypted payload with a PDF extension.
As soon as the target launches the PDF viewer, the malicious DLL file is loaded. This ultimately leads to the installation of a backdoor. To keep victims in the dark, they are shown a genuine PDF document as a diversion.
Furthermore, the attackers also exploit a Windows vulnerability known as CVE-2026-68820. Successful exploitation allows them to install malware that executes FudModule, Lazarus’ kernel-mode rootkit, with SYSTEM privileges, granting them full control over a compromised device.
In a second variant, targets are instructed to download a Trojanized PDF viewer to open a fake job offer. This infected PDF viewer searches opened PDF files for a hidden marker.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
When the marker is present, the application extracts the embedded payload and then loads a backdoor directly into the system’s memory. The attackers can then steal files from the device and execute system commands.
Researchers from cybersecurity firm Check Point have tracked the recent wave of Operation Dream Job since early 2026.
This wave has primarily targeted the defense sector in Europe, with a particular focus on companies operating in the aerospace and aviation industries and organizations involved in military technologies such as surveillance sensors, drones, and robotics.
In at least one case, the hackers abused a European organization’s reputation and trust to target additional victims using compromised accounts.
“Our findings highlight Lazarus’s continued evolution toward stealthier and more resilient operations, combining new delivery techniques, modular malware, zero-day exploitation, and compromised web infrastructure,” Check Point concludes.