Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company
ID: 0d9f1b9e-fb5f-5186-af2b-ff6436475993
STIX ID: report--0d9f1b9e-fb5f-5186-af2b-ff6436475993
Feed Name: WeLiveSecurity (ESET Research)
**ESET describes a targeted Lazarus (North Korea-linked) cyberespionage campaign against an aerospace company in Spain that used LinkedIn spearphishing and trojanized "coding challenge" executables to deploy a downloader (NickelLoader), a mini-BlindingCan RAT, and a newly identified sophisticated RAT named LightlessCan; the report details DLL side‑loading execution chains, execution guardrails and strong encryption to restrict payload decryption to intended hosts, provides extensive IoCs (file hashes, file paths, C2 domains/IPs), and maps observed behaviors to MITRE ATT&CK techniques.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
