HomeSecurityLazarus hackers targeted European defense companies

Lazarus hackers targeted European defense companies

A new, highly targeted cyber campaign by the notorious Lazarus Group is at the center of global attention. ESET researchers have revealed that North Korean hackers breached three European defense companies , leveraging fake job offers through the Operation DreamJob social engineering program .

hackers Lazarus European defense companies

This new campaign, detected in late March, appears to have had a clear strategic goal: gaining access to companies involved in the development of UAV (unmanned aerial vehicle) technologies — an area of ​​particular interest to North Korea, which is trying to create its own drone fleet inspired by Western models.

The "bait" of career: How Operation DreamJob works

Operation DreamJob is not new. The Lazarus team has been implementing it for years with remarkable success. The method is simple but effective: hackers pose as recruiters from large companies — often even using fake LinkedIn profiles — and approach highly qualified employees with tempting “job offers.”

See also: Hackers abuse OAuth apps to access cloud accounts

Once the potential victim opens the attached file or runs the application they are sent, the malware is silently installed on the system, giving the attackers full access to the company’s networks. This technique has been used before against cryptocurrency companies, journalists, and developers, but this time the targets appear to be more strategic than ever.

UAVs and geopolitics: Why North Korea matters

The choice of targets related to drone is not accidental. ESET points out that North Korea is investing massively in the development of UAVs for military purposes, trying to bridge the technological gap that separates it from the West.

Lazarus hackers targeted European defense companies

Of the three companies affected, one is active in the manufacture of drones, while the other two design software for drones, which are already being used on the Ukrainian front through European military assistance.

Although ESET did not disclose the extent of the attack's success, it is clear that the hackers sought access to technological data and UAV blueprints, possibly with the aim of reverse engineering and transferring know-how to Pyongyang's state programs.

Technical analysis: Trojanized tools and stealth tactics

Researchers found that the infection chain started by executing common open-source tools that had been modified with the trojan. Among them were infected versions of MuPDF, Notepad++, as well as plugins for WinMerge and TightVNC Viewer.

See also: 'Jingle Thief' hackers exploit cloud infrastructure

The attack was based on DLL hijacking — a method that allows malicious code to be injected via legitimate applications. Once activated, the payload is decrypted and executed in system memory, avoiding detection by antivirus software.

The final stage involves the installation of the ScoringMathTea RAT (Remote Access Trojan), which establishes a connection to a Command & Control (C2), allowing hackers to execute commands, collect data , and install new malware.

In some variants, Lazarus used BinMergeLoader (MISTPEN) — an alternative tool that exploits the Microsoft Graph API to download additional payloads, giving attackers flexibility and stealth.

The ScoringMathTea RAT: A Cyberespionage Weapon

The ScoringMathTea RAT, first detected in 2023, supports over 40 commands, allowing hackers to manipulate files, execute processes, collect system data, and maintain a prolonged presence in the target's environment .

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Lazarus hackers targeted European defense companies

ESET notes that despite the extensive publicity of Operation DreamJob in recent years, the tactic remains remarkably effective . The psychological approach through “attractive job offers” proves to be more persuasive than traditional phishing emails, especially when hackers invest in carefully crafted profiles and realistic communication scenarios .

See also: Hackers targeted over 250 Magento stores via Adobe Commerce vulnerability

The growing threat of Lazarus to Europe

Operation DreamJob is part of a long series of cyber espionage operations by the Lazarus group, which operates under the auspices of the North Korean state.

Beyond economic benefits, these attacks have a clear strategic dimension: the collection of technological secrets that can enhance the defense and missile capabilities .

ESET has published a full set of indicators of compromise (IoCs) to identify related attacks, warning that Lazarus shows no signs of abating.

With Europe increasing its military production due to geopolitical tensions, experts believe it is almost certain that such targeted espionage campaigns will intensify even further in the coming years.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS