Lazarus Group Targets European UAV Sector in New Operation DreamJob Campaign
ESET researchers have identified a new wave of cyberespionage attacks conducted by the North Korea-aligned Lazarus group, specifically targeting European companies in the defense and unmanned aerial vehicle (UAV) sectors. This campaign, categorized under Operation DreamJob, utilizes social engineering tactics involving fake job offers to deliver malware. The attackers trojanized open-source projects and deployed payloads such as ScoringMathTea, a remote access trojan granting full control over compromised systems. Notably, the malware included components named DroneEXEHijackingLoader.dll, indicating a specific focus on drone technology. The primary objective appears to be the theft of proprietary information and manufacturing know-how to support North Korea’s efforts to scale its drone program. The attacks targeted three distinct entities in Southeastern and Central Europe, including a metal engineering firm, an aircraft component manufacturer, and a defense company. This activity highlights the group's evolution in using new libraries for DLL proxying and selecting different open-source projects for improved evasion. The findings underscore the geopolitical implications of state-sponsored cyber theft aimed at accelerating military technological capabilities through illicit means.
Wire timeline
Lazarus Group Targets European UAV Sector in New Operation DreamJob Campaign
ESET researchers have identified a new wave of cyberespionage attacks conducted by the North Korea-aligned Lazarus group, specifically targeting European companies in the defense and unmanned aerial vehicle (UAV) sectors. This campaign, categorized under Operation DreamJob, utilizes social engineering tactics involving fake job offers to deliver malware. The attackers trojanized open-source projects and deployed payloads such as ScoringMathTea, a remote access trojan granting full control over compromised systems. Notably, the malware included components named DroneEXEHijackingLoader.dll, indicating a specific focus on drone technology. The primary objective appears to be the theft of proprietary information and manufacturing know-how to support North Korea’s efforts to scale its drone program. The attacks targeted three distinct entities in Southeastern and Central Europe, including a metal engineering firm, an aircraft component manufacturer, and a defense company. This activity highlights the group's evolution in using new libraries for DLL proxying and selecting different open-source projects for improved evasion. The findings underscore the geopolitical implications of state-sponsored cyber theft aimed at accelerating military technological capabilities through illicit means.
WeLiveSecurity