logo

North Korean Lazarus hackers targeted European defense companies

ID: 43a316f8-351e-541a-800f-54a78de777e6

STIX ID: report--43a316f8-351e-541a-800f-54a78de777e6

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-10-23

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

ESET reported that the North Korean Lazarus Group ran Operation DreamJob in late March, using fake recruiter lures to target three European defense companies involved in UAV technology; attackers distributed trojanized open-source applications and plugins that loaded malicious DLLs via DLL sideloading, employed in-memory loading routines, and deployed the ScoringMathTea RAT or a loader (BinMergeLoader/MISTPEN) that abuses Microsoft Graph API for additional payloads, with ESET publishing extensive IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.