logo

Lazarus Hackers Actively Attacking European Drone Manufacturing Companies

ID: 1a3b878b-7efe-5aa8-872a-499c1e88b296

STIX ID: report--1a3b878b-7efe-5aa8-872a-499c1e88b296

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-01-26

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

Lazarus (HIDDEN COBRA) has conducted Operation DreamJob since March 2025, targeting Central and Southeastern European drone manufacturers and defense contractors with social-engineered fake job offers that deliver trojanized applications (e.g., TightVNC, MuPDF, WinMerge plugins) and a sophisticated RAT called ScoringMathTea; attackers use DLL side-loading and in-memory-only encryption to evade detection and steal UAV design IP and components data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.