North Korean Hackers Attacking Unmanned Aerial Vehicle Industry to Steal Confidential Data
ID: 3e1612fe-705b-5a8d-bec9-1c32a2f7f227
STIX ID: report--3e1612fe-705b-5a8d-bec9-1c32a2f7f227
Feed Name: cybersecurityNews.com
**Operation DreamJob (Lazarus):** North Korean state-sponsored Lazarus actors targeted Central and Southeastern European UAV developers beginning March 2025, using fraudulent job offers to deliver trojanized PDF readers and trojanized open-source tools (TightVNC, MuPDF, WinMerge plugins, Notepad++ plugins). The attackers deployed multi-stage droppers (including DroneEXEHijackingLoader.dll and BinMergeLoader) and the ScoringMathTea RAT to achieve file/process control and exfiltration, relied on DLL side-loading and reflective in-memory injection, employed AES-128/ChaCha20 and IDEA+base64 for layered encryption, and used compromised WordPress-hosted servers and domains such as coralsunmarine.com, mnmathleague.org, and spaincaramoon.com for C2 and payload delivery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
