Lazarus Hackers Actively Attacking European Drone Manufacturing Companies
The hacking group Lazarus, also known as HIDDEN COBRA, has initiated a series of targeted attacks on European drone manufacturers and defense contractors. This campaign, referred to as Operation DreamJob, began in late March 2025 and is focused on…
The hacking group Lazarus, also known as HIDDEN COBRA, has initiated a series of targeted attacks on European drone manufacturers and defense contractors. This campaign, referred to as Operation DreamJob, began in late March 2025 and is focused on organizations developing unmanned aerial vehicle (UAV) technology in Central and Southeastern Europe.
This activity is part of a broader strategic effort by North Korea to enhance its domestic drone capabilities, following increased investments in modern warfare technology observed during the Russia-Ukraine conflict. The campaign is aimed at acquiring proprietary manufacturing information and intellectual property from the aerospace and defense sectors.
Three European companies have been identified as targets, with at least two significantly involved in the design of advanced single-rotor drones and the production of critical UAV components deployed in conflict zones. The attacks align with North Korea's reported initiatives to mass-produce combat and reconnaissance drones akin to Western models such as the MQ-9 Reaper and RQ-4 Global Hawk.
The hacking group Lazarus, also known as HIDDEN COBRA, has initiated a series of targeted attacks on European drone manufacturers and defense contractors.
According to analysts from Welivesecurity, the malware infrastructure used in these attacks employs advanced delivery mechanisms to circumvent traditional security defenses. The attacks begin with social engineering tactics, including fake job offers, to trick employees into downloading trojanized documents. Once executed, the malware deploys specialized tools for persistent access and avoiding detection on compromised systems.
The primary infection mechanism involves DLL side-loading, where legitimate Windows applications are exploited to load malicious libraries without triggering security alerts. The attackers have embedded their malware into trojanized versions of popular open-source software, such as TightVNC Viewer, MuPDF reader, and WinMerge plugins. A notable dropper contained the internal filename DroneEXEHijackingLoader.dll, indicating the campaign's focus on drone technology.
The main payload, ScoringMathTea, is a remote access trojan that grants attackers comprehensive control over compromised machines. This malware provides approximately 40 commands for system manipulation, file exfiltration, and further payload deployment. ScoringMathTea is particularly dangerous due to its ability to remain encrypted on disk, decrypting only in memory during execution, which complicates detection through traditional file-based methods.
Based on reporting by Cyber Security News.
