logo

Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company

ID: 0d9f1b9e-fb5f-5186-af2b-ff6436475993

STIX ID: report--0d9f1b9e-fb5f-5186-af2b-ff6436475993

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2023-09-29

Date Updated: 2026-05-01

...
...

**ESET describes a targeted Lazarus (North Korea-linked) cyberespionage campaign against an aerospace company in Spain that used LinkedIn spearphishing and trojanized "coding challenge" executables to deploy a downloader (NickelLoader), a mini-BlindingCan RAT, and a newly identified sophisticated RAT named LightlessCan; the report details DLL side‑loading execution chains, execution guardrails and strong encryption to restrict payload decryption to intended hosts, provides extensive IoCs (file hashes, file paths, C2 domains/IPs), and maps observed behaviors to MITRE ATT&CK techniques.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.