logo

North Korea’s Lazarus group attacked three companies involved in drone development

ID: 27d1200a-7d66-51a8-ba16-3d56460cb129

STIX ID: report--27d1200a-7d66-51a8-ba16-3d56460cb129

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2025-10-23

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

ESET reported that North Korea’s Lazarus group ran Operation DreamJob in late March, using fake high-profile job-offer documents and a trojanized PDF reader to deploy the ScoringMathTea RAT against three Europe-based companies in the drone and defense supply chain, likely seeking UAV manufacturing know-how; investigators observed a dropper DLL named "DroneEXEHijackingloader.dll" and published associated binaries and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.