The recruiter was fake. The Windows zero-day was real.

Share this content

August 13, 2026

It starts with a message most people would welcome: a recruiter, a great role, a job description attached as a PDF. To read it, you are pointed to a special PDF viewer. You install it, open the file, and the attacker now owns your machine at the deepest level Windows has.

That is the latest wave of Operation Dream Job, a long-running Lazarus campaign that Check Point Research documented on Aug. 11, the same day Microsoft shipped the fix.

Dreamjob

What happened

  • The lure. Fake recruiters approached employees at defense, aerospace and aviation organizations, with confirmed compromises in Europe. The attackers also built impersonation websites and used search engine optimization to push their tools higher in search results.
  • The trojan. Targets were steered to install SecurityPDF, a modified PDF viewer built to open attacker-crafted job documents and launch a new backdoor Check Point named Troy.
  • The zero-day. Lazarus exploited CVE-2026-68820, a privilege escalation flaw in the Windows AFD.sys driver, to gain kernel access. Reporting suggests the group had a working exploit for roughly five weeks before the patch.
  • The rootkit. With kernel access, the attackers deployed a new version of FudModule, Lazarus' rootkit that switches off security tools from below.

Why it matters for Texas institutions

Texas universities run some of the country's largest aerospace, engineering and defense research programs. Faculty, postdocs and graduate students in those labs are exactly who Dream Job recruiters look for, and their laptops often hold sensitive or export-controlled work.

Students are part of the picture too. Fall is recruiting season, and a polished offer that asks you to install a "secure" document viewer will not look strange to someone sending out dozens of applications. Staff in HR and research administration face a mirror version of the same trick from fake candidates.

What your institution should do

  • Confirm the August patch landed everywhere. Prioritize lab machines, research workstations and anything not centrally managed.
  • Block unapproved software installs. Application control or standard-user accounts stop the "install this viewer" step cold.
  • Make recruiting part of awareness training. Teach that no legitimate employer requires a special program to read a job description.
  • Watch for kernel-level tampering. EDR alerts that a security agent stopped or was unloaded deserve an immediate look.
  • Give research security a heads-up. Labs doing defense or aerospace work should hear about this campaign directly.

RSOC is here to help

RSOC can help you find unpatched systems, review EDR coverage on research networks and tailor phishing awareness for job-search scams. Contact rsoc@utexas.edu.

Sources: Check Point Research · HivePro advisory · Tech Insider