Lazarus Hackers Target European Drone Manufacturers in Active Campaign
ID: d8fd1c34-84a4-59cb-9752-81a16a5654a6
STIX ID: report--d8fd1c34-84a4-59cb-9752-81a16a5654a6
Feed Name: GBHackers
Threat Score
The report details a North Korean Lazarus APT campaign called Operation DreamJob that targets European UAV and defense contractors using fraudulent job offers and trojanized legitimate applications (e.g., MuPDF, Notepad++ plugins) to deploy ScoringMathTea RAT and BinMergeLoader, provides IoCs (multiple SHA-1 hashes and filenames), attribution evidence, and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
