This North Korean recruitment scam was so convincing it even fooled Google

Fake sites were popping up at the top of search engine results pages

by · TechRadar

News By Sead Fadilpašić Published 12 August 2026

(Image credit: Shutterstock)

Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter


  • Lazarus expanded Dream Job with a zero‑day, new backdoor, and advanced relays
  • Fake job lures, trojanized PDFs, and spoofed sites enabled high‑level compromises
  • Targets included defense and aerospace firms, prompting stronger phishing awareness

Security experts from Check Point Research say they have uncovered a new wave of "Operation Dream Job" attacks, leveraging a previously undocumented backdoor, a brand new Windows zero-day vulnerability, and a never-before-seen webshell/relay.

Lazarus Group is a hacking collective on the payroll of the North Korean government. It is a state-sponsored threat actor known for targeting cryptocurrency developers and other professionals in the Web3 industry, stealing their tokens and using the money to fund the country’s weapons program and the wider state apparatus.

It is also known for running Operation Dream Job - a hacking campaign that’s been going on for years, and that lures victims with highly lucrative but bogus job opportunities.

Latest Videos FromTechRadarWatch full video here:

What is Operation Dream Job?

The scam works like this: the attackers come up with a fake company, often in the software development, defense, aerospace, or military industries.

They create the fake company’s website, LinkedIn account, as well as fake people supposedly employed there. Then, they reach out to their targets, offering great working conditions, amazing salaries, and an opportunity to work on exciting projects.

Victims that take the bait are then led through a series of “interviews” and somewhere along the line, they are either given weaponized PDF files or asked to download and run executables and other code, as part of a “training exercise” or “skill evaluation”. At this moment, the victims get compromised, while the attackers gain access to their actual employers’ infrastructure.

From there, the ending can be relatively different. Lazarus has, on at least one occasion, stolen more than a billion dollars in cryptocurrency from one of its victims.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors