A new, particularly worrying wave of cyberattacks has begun in Europe, focusing on the rapidly growing sector of unmanned aerial vehicles (UAVs) and drones. Behind the attacks is the notorious Lazarus, also known as HIDDEN COBRA, which is directly linked to the North Korean and is considered one of the most sophisticated state-sponsored cyberespionage groups in the world.

The new campaign, codenamed Operation DreamJob, appeared in late March 2025 and systematically targets European companies active in the development of drone technology, mainly in Central and Southeastern Europe.
Strategic objective: UAV technology and defense know-how
According to cybersecurity analysts, the attacks are not isolated incidents, but part of a broader North Korean strategy to accelerate its domestic drone program. The intensification of these efforts is directly linked to modern military developments, especially after the role of UAVs in the Russia-Ukraine war, where drones have become crucial in both reconnaissance and offensive operations.
See also: Konni hackers use AI-generated PowerShell backdoor
The campaign is considered a significant escalation of cyberespionage tactics, with the clear aim of stealing intellectual property, manufacturing plans, know-how and critical technical data from the aerospace and defense sectors.
Lazarus: European companies in the spotlight
So far, at least three European companies have been confirmed as Lazarus targets. Two of them are actively involved in the design of advanced single-rotor drones and the production of critical UAV components, which are already used in active conflict zones.
The timing of the attacks is not considered coincidental. It coincides with reports that North Korea is seeking to mass-produce combat drones, technologically comparable to Western models such as the MQ-9 Reaper and RQ-4 Global Hawk.

Social engineering: When fraud starts from "work"
The attack begins not with a technical breach, but with social engineering. The attackers use fake job advertisements, presenting alleged career opportunities in top technology positions. The messages are professionally structured, persuasive, and tailored to the profiles of employees at the targeted companies.
See also: Gmail, Facebook, Instagram, TikTok credentials leaked online
Victims are asked to download documents or “assessment files”that contain trojan-like malware. In this way, attackers exploit human trust and ambition, bypassing traditional digital defenses.
Technical infrastructure and sophisticated infection methods
The main infection mechanism is based on the technique DLL side-loading, where legitimate Windows applications are used to load malicious libraries without triggering security systems. Hackers have embedded the malware in modified versions of popular open source software, such as TightVNC Viewer, MuPDF reader, and WinMerge.
Of particular interest is a dropper with an internal name DroneEXEHijackingLoader.dll, which directly reveals the campaign's theme and focus on UAV technology.

ScoringMathTea: The "invisible" remote access weapon
The main payload of the attacks is ScoringMathTea, a sophisticated remote access trojan (RAT) that gives attackers complete control over compromised systems. It has more than 40 commands for system administration, file extraction, activity monitoring, and deployment of additional malware.
See also: Sandworm hackers targeted Polish energy systems
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What makes it extremely dangerous is its concealment technique: it remains fully encrypted on disk and is only decrypted in memory during execution, making detection with traditional antiviruses practically ineffective without advanced behavioral analysis systems.
A new field of cyberwarfare
Operation DreamJob is not just another cyberattack, but a sign of a new phase of digital espionage competition. The targeted attack on European defense technology shows that cyberspace has become a key arena of strategic conflict, where information and know-how are as valuable as weapons.
For European defense and technology industries, the message is clear: cybersecurity is no longer just a technical issue, but a critical factor of national and geopolitical security.
