Lazarus Hackers Actively Attacking European Drone Manufacturing Companies
ID: 1a3b878b-7efe-5aa8-872a-499c1e88b296
STIX ID: report--1a3b878b-7efe-5aa8-872a-499c1e88b296
Feed Name: cybersecurityNews.com
Threat Score
Lazarus (HIDDEN COBRA) has conducted Operation DreamJob since March 2025, targeting Central and Southeastern European drone manufacturers and defense contractors with social-engineered fake job offers that deliver trojanized applications (e.g., TightVNC, MuPDF, WinMerge plugins) and a sophisticated RAT called ScoringMathTea; attackers use DLL side-loading and in-memory-only encryption to evade detection and steal UAV design IP and components data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
