ESET has identified a new wave of the Operation DreamJob campaign, attributable to the North Korean group Lazarus, which has affected European companies in the defense sector, including an Italian company, some of which are heavily involved in the development of unmanned aerial vehicles (UAVs)
Researchers of ESET, a global leader in the cybersecurity market, recently observed new activity linked to Operation DreamJob, a campaign by the North Korea-aligned Lazarus Group. Several attacks have targeted defense companies in central and southeastern Europe, some of which produce drones, suggesting a possible link to Pyongyang's recent efforts to boost its drone development program.
The attacks detected in the field affected three companies in the defense sector in succession. The initial access was almost certainly obtained through social engineering techniques, exploiting open source projects on GitHub and introducing ScoringMathTea, a Remote Access Trojan (RAT) type backdoor into the victim systems, which allows full control of the compromised devices. The main objective was allegedly the exfiltration of sensitive information and technical know-how.
In the context of Operation DreamJob, the social engineering tactic revolves around tempting but fake job offers, accompanied by decoy documents and compromised PDF readers. ESET attributes the activity to the Lazarus group with a high degree of certainty, both for the type of victims - in line with the objectives of previous campaigns (aerospace, defense, engineering) - and for the operational methods already observed.
The three organizations involved produce different types of military equipment, many of which are currently used in Ukraine as part of European military assistance. During the period of observation of Operation DreamJob activities, North Korean soldiers were deployed in Russia, with the task of supporting Moscow in the Kursk front. It is therefore plausible that the operation was aimed at gathering information on Western weapons systems used in the Russian-Ukrainian conflict. In general, affected companies develop military equipment similar to that made in North Korea, which may aim to refine its designs and manufacturing processes by acquiring classified technical information. The interest in the drone sector is particularly significant: recent news indicates that Pyongyang is investing heavily in the domestic production of UAVs, often based on reverse engineering and intellectual property theft.
"We believe it is likely that Operation DreamJob was at least partly aimed at the theft of proprietary information and manufacturing know-how related to drones. An explicit reference to drones identified in one of the droppers further strengthens this hypothesis," explains Peter Kálnai, an ESET researcher who discovered and analyzed the attacks. “We have collected evidence that one of the affected companies is involved in the production of at least two UAV models used in Ukraine, and in the supply chain of advanced single-rotor drones, a type on which North Korea is actively working,” adds Alexis Rapin, ESET cyberthreat analyst.
The Lazarus group is known for its intense activity and for employing multiple backdoors against different targets. To avoid detection, its campaigns involve the use of droppers, loaders and simple downloaders that precede the execution of the main payload. In this case, the attackers integrated the malicious routines into open source projects on GitHub.
The main payload, ScoringMathTea, is a complex RAT that supports approximately 40 commands. It was first spotted on VirusTotal in samples from Portugal and Germany in October 2022, where a dropper presented itself as an Airbus-themed lure. Its capabilities include manipulating files and processes, gathering system information, opening TCP connections, and downloading new payloads from command and control (C&C) servers.
According to ESET telemetry, ScoringMathTea has been observed in attacks against an Indian technology company (January 2023), a Polish defense company (March 2023), a British industrial automation company (October 2023), and an Italian aerospace company (September 2025). It is therefore one of the main payloads used in Operation DreamJob campaigns.
The most significant evolution of Lazarus concerns the introduction of new libraries for DLL proxying and the choice of new open source projects to be compromised with malicious code to improve evasion capabilities.
"Over the past three years, Lazarus has maintained a consistent modus operandi, deploying its main ScoringMathTea payload and adopting similar methods to Trojanize open source applications. This predictable but effective strategy ensures a sufficient level of polymorphism to evade detection systems, although it is not enough to completely hide the group's identity and make attribution more complex," concludes Kálnai.
The Lazarus group (also known as HIDDEN COBRA) is a North Korea-linked APT group active since at least 2009, responsible for numerous high-profile incidents. It is characterized by a notable variety of campaigns and a heterogeneous approach that covers the three main areas of cybercrime: espionage, sabotage and economic activities.
Operation DreamJob is the code name used to identify Lazarus campaigns based primarily on social engineering with fake job offers, often for high-profile positions. The main targets belong to the aerospace and defense sectors, followed by engineering, technology and media.






