North Korea-linked Lazarus hackers are exploiting a Windows zero-day vulnerability and luring targets with fake job offers, according to researchers from Check Point. The activity is tied to Operation Dream Job, a long-running campaign in which attackers pose as recruiters and use decoy documents to entice victims.
In the reported intrusions, attackers combine social engineering with malware delivered through trojanized content, including a PDF-related decoy document that researchers say referenced a Lockheed Martin job description. Help Net Security reports that Check Point identified the campaign’s use of a Windows zero-day exploit, while Bleeping Computer reports the specific vulnerability as CVE-2026-68820.
Across the sources, the key focus is on targeting: both accounts describe attacks primarily aimed at the defense sector and describe the job-offer recruitment theme as a central element of the lures. The outlets differ mainly in the level of technical detail provided, with one emphasizing the campaign’s components and the other naming the affected Windows vulnerability.