Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Lazarus Hackers Actively Attacking European Drone Manufacturing Companies

The hacking group Lazarus, also known as HIDDEN COBRA, has initiated a series of targeted attacks on European drone manufacturers and defense contractors. This campaign, referred to as Operation DreamJob, began in late March 2025 and is focused on…

The hacking group Lazarus, also known as HIDDEN COBRA, has initiated a series of targeted attacks on European drone manufacturers and defense contractors. This campaign, referred to as Operation DreamJob, began in late March 2025 and is focused on organizations developing unmanned aerial vehicle (UAV) technology in Central and Southeastern Europe.

This activity is part of a broader strategic effort by North Korea to enhance its domestic drone capabilities, following increased investments in modern warfare technology observed during the Russia-Ukraine conflict. The campaign is aimed at acquiring proprietary manufacturing information and intellectual property from the aerospace and defense sectors.

Three European companies have been identified as targets, with at least two significantly involved in the design of advanced single-rotor drones and the production of critical UAV components deployed in conflict zones. The attacks align with North Korea's reported initiatives to mass-produce combat and reconnaissance drones akin to Western models such as the MQ-9 Reaper and RQ-4 Global Hawk.

The hacking group Lazarus, also known as HIDDEN COBRA, has initiated a series of targeted attacks on European drone manufacturers and defense contractors.
Amanda Parks · Thehackingpost

According to analysts from Welivesecurity, the malware infrastructure used in these attacks employs advanced delivery mechanisms to circumvent traditional security defenses. The attacks begin with social engineering tactics, including fake job offers, to trick employees into downloading trojanized documents. Once executed, the malware deploys specialized tools for persistent access and avoiding detection on compromised systems.

The primary infection mechanism involves DLL side-loading, where legitimate Windows applications are exploited to load malicious libraries without triggering security alerts. The attackers have embedded their malware into trojanized versions of popular open-source software, such as TightVNC Viewer, MuPDF reader, and WinMerge plugins. A notable dropper contained the internal filename DroneEXEHijackingLoader.dll, indicating the campaign's focus on drone technology.

Advertisement

The main payload, ScoringMathTea, is a remote access trojan that grants attackers comprehensive control over compromised machines. This malware provides approximately 40 commands for system manipulation, file exfiltration, and further payload deployment. ScoringMathTea is particularly dangerous due to its ability to remain encrypted on disk, decrypting only in memory during execution, which complicates detection through traditional file-based methods.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories