North Korean Hackers Target UAV Industry to Steal Confidential Data
ESET researchers have identified a cyberespionage campaign targeting European defense companies involved in unmanned aerial vehicle (UAV) technology. The campaign, attributed to the North Korea-aligned Lazarus group, focuses on acquiring proprietary…
ESET researchers have identified a cyberespionage campaign targeting European defense companies involved in unmanned aerial vehicle (UAV) technology. The campaign, attributed to the North Korea-aligned Lazarus group, focuses on acquiring proprietary manufacturing data and design specifications from key players in the drone industry.
The campaign, known as Operation DreamJob, was observed starting in late March 2025. It targeted at least three European defense contractors across Southeastern and Central Europe, including a metal engineering firm, an aircraft component manufacturer, and a dedicated defense company. These entities are significantly involved in UAV development and production.
Operation DreamJob is characterized by the use of social engineering tactics disguised as prestigious employment opportunities. Victims received legitimate-looking job descriptions accompanied by trojanized PDF readers, which established initial access. The attackers used malicious loading routines incorporated into open-source projects from GitHub, leveraging the Microsoft Graph API with Microsoft API tokens for authentication.
Throughout 2025, the campaign utilized trojanized versions of TightVNC Viewer, MuPDF reader, and popular developer tools, including WinMerge plugins and Notepad++ extensions. A notable indicator was a dropper containing the internal DLL name "DroneEXEHijackingLoader.dll," suggesting a focus on UAV-related intellectual property theft.
Strategic Alignment with North Korean Drone Expansion
The operation aligns with North Korea's documented expansion of its domestic drone manufacturing capabilities. Intelligence indicates Pyongyang is investing in developing advanced UAV systems, including reconnaissance platforms and combat drones resembling American counterparts. This activity coincided with North Korean troops being deployed alongside Russian forces in Ukraine, providing exposure to Western military equipment.
The primary malware deployed was ScoringMathTea, a remote access trojan supporting approximately 40 commands. It allows attackers to manipulate files, execute code, harvest system information, and maintain command-and-control communication through compromised servers. The operation highlights vulnerabilities in technology sectors, emphasizing the need for improved employee awareness regarding social engineering threats.
Organizations in aerospace, engineering, and defense sectors should prioritize recruitment communication verification and implement advanced endpoint detection systems. These systems should identify trojanized applications and malicious DLL side-loading techniques common in Operation DreamJob campaigns.
SHA-1 Filename Detection Description
28978E987BC59E75CA22562924EAB93355CF679E TSMSISrv.dll Win64/NukeSped.TL QuanPinLoader.
5E5BBA521F0034D342CC26DB8BCFECE57DBD4616 libmupdf.dll Win64/NukeSped.TE A loader disguised as a MuPDF rendering library v3.3.3.
ESET researchers have identified a cyberespionage campaign targeting European defense companies involved in unmanned aerial vehicle (UAV) technology.
B12EEB595FEEC2CFBF9A60E1CC21A14CE8873539 radcui.dll Win64/NukeSped.TO A dropper disguised as a RemoteApp and Desktop Connection UI Component library.
26AA2643B07C48CB6943150ADE541580279E8E0E HideFirstLetter.DLL Win64/NukeSped.TO BinMergeLoader.
0CB73D70FD4132A4FF5493DAA84AAE839F6329D5 libpcre.dll Win64/NukeSped.TP A loader that is a trojanized libpcre library.
03D9B8F0FCF9173D2964CE7173D21E681DFA8DA4 webservices.dll Win64/NukeSped.RN A dropper disguised as a Microsoft Web Services Runtime library.
71D0DDB7C6CAC4BA2BDE679941FA92A31FBEC1FF N/A Win64/NukeSped.RN ScoringMathTea.
87B2DF764455164C6982BA9700F27EA34D3565DF webservices.dll Win64/NukeSped.RW A dropper disguised as a Microsoft Web Services Runtime library.
E670C4275EC24D403E0D4DE7135CBCF1D54FF09C N/A Win64/NukeSped.RW ScoringMathTea.
B6D8D8F5E0864F5DA788F96BE085ABECF3581CCE radcui.dll Win64/NukeSped.TF A loader disguised as a RemoteApp and Desktop Connection UI Component library.
5B85DD485FD516AA1F4412801897A40A9BE31837 RCX1A07.tmp Win64/NukeSped.TH A loader of an encrypted ScoringMathTea.
B68C49841DC48E3672031795D85ED24F9F619782 TSMSISrv.dll Win64/NukeSped.TL QuanPinLoader.
AC16B1BAEDE349E4824335E0993533BF5FC116B3 cache.dat Win64/NukeSped.QK A decrypted ScoringMathTea RAT.
2AA341B03FAC3054C57640122EA849BC0C2B6AF6 msadomr.dll Win64/NukeSped.SP A loader disguised as a Microsoft DirectInput library.
CB7834BE7DE07F89352080654F7FEB574B42A2B8 ComparePlus.dll Win64/NukeSped.SJ A trojanized Notepad++ plugin disguised as a Microsoft Web Services Runtime library. A dropper from VirusTotal.
262B4ED6AC6A977135DECA5B0872B7D6D676083A tzautosync.dat Win64/NukeSped.RW A decrypted ScoringMathTea, stored encrypted on the disk.
086816466D9D9C12FCADA1C872B8C0FF0A5FC611 N/A Win64/NukeSped.RN ScoringMathTea.
2A2B20FDDD65BA28E7C57AC97A158C9F15A61B05 cache.dat Win64/NukeSped.SN A downloader similar to BinMergeLoader built as a trojanized NPPHexEditor plugin.
Based on reporting by GBHackers.
