2 N.Korean govt-backed hackers exploited Chrome bug: Google

  • State-Sponsored Collaboration: Google TAG has identified two distinct North Korean hacker groups sharing a unified “exploit kit” to weaponize a Chrome Remote Code Execution (RCE) vulnerability.
  • AI-Powered Social Engineering: In 2026, these actors have evolved “Operation Dream Job” using Large Language Models (LLMs) to create hyper-personalized job lures from major tech firms like Google and Disney.
  • Massive Targeting Scale: Current 2026 data shows these campaigns now target over 1,500 entities annually, focusing on cryptocurrency “drainer” exploits and harvesting data for future post-quantum decryption.

The digital perimeter of the global workforce is under a sophisticated, AI-enhanced siege. Google’s Threat Analysis Group (TAG) recently declassified intelligence revealing that two North Korean government-backed hacking collectives are actively exploiting a critical Chrome browser vulnerability to infiltrate high-value sectors. This isn’t a mere technical glitch; it is a meticulously choreographed campaign of cyber-espionage that blends zero-day exploits with the chilling precision of modern social engineering.

Security researchers suspect these two groups, though operating with different mission sets, share a centralized supply chain. By utilizing the same exploit kit, they have streamlined the process of compromising news media, fintech, and IT infrastructure on a global scale. As Google says it fixed more Chrome bugs in June via AI, the arms race between state-sponsored actors and automated defense systems has reached a fever pitch in 2026.

The Evolution of ‘Operation Dream Job’ in the AI Era

The first of the two identified campaigns, historically known as “Operation Dream Job,” has undergone a radical transformation. While early iterations relied on generic phishing templates, the 2026 version utilizes generative AI to craft indistinguishable recruitment lures. Targeted individuals—often software engineers or journalists—receive emails purportedly from recruiters at Disney, Oracle, or Google offering lucrative positions.

These communications lead to spoofed versions of legitimate career sites like Indeed and ZipRecruiter. Once a victim clicks, a hidden iframe triggers the RCE exploit kit. Unlike previous years where the scale was limited, current estimates suggest these actors are now targeting upwards of 1,500 entities annually, leveraging automated LLM agents to maintain thousands of “active” recruitment conversations simultaneously.

Pro-Tip: Verification in 2026

Always verify job offers via a secondary, authenticated channel. State-sponsored actors now use AI-generated video avatars in “preliminary interviews” to build trust before delivering a malicious payload. If a recruiter asks you to download a “coding challenge” or a “secure PDF” outside of official portals, treat it as a high-risk event.

Operation AppleJeus: Targeting the Fintech Backbone

The second group focuses on the lucrative intersection of decentralized finance (DeFi) and traditional fintech. Dubbed “Operation AppleJeus,” this campaign has moved beyond simple malware. In 2026, the focus has shifted to “smart contract drainers”—malicious code that, once executed through a compromised Chrome session, can bypass multi-signature protections.

Google noted that these hackers have compromised legitimate fintech websites to host their exploit kits, turning trusted industry portals into infection vectors. This group specifically targets hackers targeting security experts with fake crypto lures, recognizing that even the most technically savvy users can be caught off guard by a zero-day browser exploit.

Campaign Attribute Operation Dream Job Operation AppleJeus
Primary Target Media, IT, Software Vendors Fintech, Crypto, DeFi Users
Infection Vector AI-crafted recruitment emails Watering hole attacks on fintech sites
End Goal Espionage & Data Harvesting Financial Theft & Currency Draining

Post-Quantum Harvesting: A Long-Term Threat

Beyond immediate financial gain, recent intelligence suggests a more ominous objective. Cybersecurity analysts believe North Korean actors are engaging in “Harvest Now, Decrypt Later” tactics. By exploiting Chrome bugs to gain access to internal corporate networks, they are exfiltrating vast amounts of encrypted data. While this data is currently unreadable, the aim is to retain it until quantum computing capabilities allow for its decryption, potentially exposing state secrets and intellectual property in the coming decade.

“The convergence of browser-level exploits and hyper-personalized AI lures represents a paradigm shift in state-sponsored activity. We are no longer defending against scripts; we are defending against automated, intelligent adversaries.”
— Senior Researcher, Google Threat Analysis Group

Google has responded by adding all identified malicious domains to its “Safe Browsing” service and issuing “government-backed attacker” alerts to thousands of Workspace users. For a deeper technical dive into the specific memory corruption vulnerabilities exploited, you can view the official Google TAG security disclosure. As we move deeper into 2026, the reliance on AI for both attack and defense will define the survival of digital infrastructure.

More From Category

More Stories Today