The email looks like a recruiter reaching out about a role at a real privacy technology company. The PDF viewer it asks you to install looks like a normal PDF viewer. Neither of those things is true, and by the time an aerospace or defence employee realises that, Lazarus Group already has SYSTEM-level access to their machine.
A recruiting pitch built to survive scrutiny
Check Point Research has documented a new wave of Operation Dream Job, the North Korean state-sponsored campaign’s long-running playbook of posing as recruiters at recognisable companies to approach specific employees with job opportunities. This iteration impersonates Enveil, a real privacy technology firm, and focuses specifically on the defence, aerospace and aviation sectors. Confirmed compromises include organisations headquartered in France and Germany, alongside targets in India and Brazil. Unlike a generic phishing blast, this is targeted outreach aimed at people whose access is worth the effort: engineers and staff at companies building or servicing military and aviation systems.
The payload hides inside a working PDF viewer
Targets who engage with the fake recruiting process are instructed to download SecurityPDF, a modified, trojanized version of an open-source PDF viewer. It functions normally, which is exactly the point. SecurityPDF checks any document it opens for a hidden marker, and when it finds one, it decrypts and launches malware embedded inside that specific file. The delivery mechanism is not a suspicious attachment that raises alarms on open, it is a legitimate-looking application the target installed themselves, following instructions from someone who spent time building a credible pretext first.
From privilege escalation to a rootkit, without a working patch
The exploit chain uses CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) that allows a local attacker to escalate to SYSTEM privileges. Check Point traced Lazarus’s use of this flaw back to early June, roughly two months before Microsoft shipped a fix on August 11. Once elevated, the campaign deploys a new variant of the FudModule rootkit, built on a command and control architecture that runs almost entirely on infrastructure Lazarus does not own, making it harder to attribute and take down through conventional means.
Why the defence sector’s supply chain is the real target
Defence contractors, aerospace suppliers and their subcontractors are precisely the kind of organisation that sits below the largest primes’ security budgets while still holding access to sensitive programme data, and NIS2 already places specific obligations on this sector for exactly that reason. A campaign that combines a credible recruiting pretext, a functioning trojanized application and a zero-day that predates its own patch by two months will get past standard email filtering and endpoint signatures on the first pass. The defence against it is not a single control, it is recruiting-process awareness training that treats unsolicited job outreach with the same suspicion as any other unsolicited contact, combined with application allowlisting that blocks unauthorised software installs regardless of how legitimate they look.
If your organisation operates in or supplies the defence, aerospace or aviation sector and needs a realistic assessment of how it would hold up against a targeted social engineering and zero-day campaign like this one, contact Excello Digital. We help European businesses build the endpoint controls and staff awareness programmes that catch this kind of attack before a fake job offer becomes a real breach.
