×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET Research: Lazarus Group Targets Europe's Drone Industry for Espionage Activities

Customer Press Room

ESET Research: Lazarus Group Targets Europe's Drone Industry for Espionage Activities

by Grandangolo Communications / Thursday, 30 October 2025 / Published in Eset

ESET has identified a new wave of the Operation DreamJob campaign, attributable to the North Korean group Lazarus, which has affected European companies in the defense sector, including an Italian company, some of which are heavily involved in the development of unmanned aerial vehicles (UAVs)

Researchers of ESET, a global leader in the cybersecurity market, recently observed new activity linked to Operation DreamJob, a campaign by the North Korea-aligned Lazarus Group. Several attacks have targeted defense companies in central and southeastern Europe, some of which produce drones, suggesting a possible link to Pyongyang's recent efforts to boost its drone development program.

The attacks detected in the field affected three companies in the defense sector in succession. The initial access was almost certainly obtained through social engineering techniques, exploiting open source projects on GitHub and introducing ScoringMathTea, a Remote Access Trojan (RAT) type backdoor into the victim systems, which allows full control of the compromised devices. The main objective was allegedly the exfiltration of sensitive information and technical know-how.

In the context of Operation DreamJob, the social engineering tactic revolves around tempting but fake job offers, accompanied by decoy documents and compromised PDF readers. ESET attributes the activity to the Lazarus group with a high degree of certainty, both for the type of victims - in line with the objectives of previous campaigns (aerospace, defense, engineering) - and for the operational methods already observed.

The three organizations involved produce different types of military equipment, many of which are currently used in Ukraine as part of European military assistance. During the period of observation of Operation DreamJob activities, North Korean soldiers were deployed in Russia, with the task of supporting Moscow in the Kursk front. It is therefore plausible that the operation was aimed at gathering information on Western weapons systems used in the Russian-Ukrainian conflict. In general, affected companies develop military equipment similar to that made in North Korea, which may aim to refine its designs and manufacturing processes by acquiring classified technical information. The interest in the drone sector is particularly significant: recent news indicates that Pyongyang is investing heavily in the domestic production of UAVs, often based on reverse engineering and intellectual property theft.

"We believe it is likely that Operation DreamJob was at least partly aimed at the theft of proprietary information and manufacturing know-how related to drones. An explicit reference to drones identified in one of the droppers further strengthens this hypothesis," explains Peter Kálnai, an ESET researcher who discovered and analyzed the attacks. “We have collected evidence that one of the affected companies is involved in the production of at least two UAV models used in Ukraine, and in the supply chain of advanced single-rotor drones, a type on which North Korea is actively working,” adds Alexis Rapin, ESET cyberthreat analyst.

The Lazarus group is known for its intense activity and for employing multiple backdoors against different targets. To avoid detection, its campaigns involve the use of droppers, loaders and simple downloaders that precede the execution of the main payload. In this case, the attackers integrated the malicious routines into open source projects on GitHub.

The main payload, ScoringMathTea, is a complex RAT that supports approximately 40 commands. It was first spotted on VirusTotal in samples from Portugal and Germany in October 2022, where a dropper presented itself as an Airbus-themed lure. Its capabilities include manipulating files and processes, gathering system information, opening TCP connections, and downloading new payloads from command and control (C&C) servers.

According to ESET telemetry, ScoringMathTea has been observed in attacks against an Indian technology company (January 2023), a Polish defense company (March 2023), a British industrial automation company (October 2023), and an Italian aerospace company (September 2025). It is therefore one of the main payloads used in Operation DreamJob campaigns.

The most significant evolution of Lazarus concerns the introduction of new libraries for DLL proxying and the choice of new open source projects to be compromised with malicious code to improve evasion capabilities.

"Over the past three years, Lazarus has maintained a consistent modus operandi, deploying its main ScoringMathTea payload and adopting similar methods to Trojanize open source applications. This predictable but effective strategy ensures a sufficient level of polymorphism to evade detection systems, although it is not enough to completely hide the group's identity and make attribution more complex," concludes Kálnai.

The Lazarus group (also known as HIDDEN COBRA) is a North Korea-linked APT group active since at least 2009, responsible for numerous high-profile incidents. It is characterized by a notable variety of campaigns and a heterogeneous approach that covers the three main areas of cybercrime: espionage, sabotage and economic activities.

Operation DreamJob is the code name used to identify Lazarus campaigns based primarily on social engineering with fake job offers, often for high-profile positions. The main targets belong to the aerospace and defense sectors, followed by engineering, technology and media.

Tagged under: Eset

About Grandangolo Communications

What you can read next

Michele Serra, Business Partner Development Director of Talentia Software
SentinelOne amplia il supporto per Amazon Inspector, Amazon EKS Anywhere e Amazon ECS Anywhere
ESET Recognized as the Only Challenger in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection

Customer Press Room

  • Arrow Electronics has been awarded by Equinix as Distributor of the Year 2025 for the EMEA region

    Arrow Electronics, a global supplier of technology...
  • SentinelOne makes the Purple AI Agentic Investigation solution available to all customers, bringing the latest generation AI directly into the SOC

    The investigations, started autonomously and without need...
  • Acronis TRU reveals the ongoing evolution of the INC ransomware group

    A recent report published by Acronis Threat ...
  • ESET Research investigates the Gentlemen ransomware author group and its defense evasion tools

    The Gentlemen Group develops, maintains and supplies...
  • Imprivata presents the Agentic Identity Management solution to protect and govern the access of AI agents

    Imprivata, a leading company in Ac...

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • Abstract
  • abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Imprivate
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP