Inside North Korea’s Cyber Espionage: Lazarus Group’s New “DreamJob” Attack on European Drone Companies

Listen to this Post

Featured Image

The Silent War in Cyberspace

A new digital battlefield is emerging above Europe’s skies. ESET researchers have uncovered a fresh wave of Operation DreamJob—a long-running cyber-espionage campaign orchestrated by the infamous Lazarus Group, a North Korean state-backed hacking organization. Their latest mission: infiltrate European defense companies developing unmanned aerial vehicles (UAVs) and steal the secrets behind modern drone warfare, especially those connected to Ukraine’s frontline technologies.

This operation, which resurfaced in March 2025, is more than just another cyberattack. It’s a calculated intelligence mission, blending social manipulation with sophisticated technical subterfuge. The Lazarus Group’s goal, according to ESET’s assessment, is to obtain proprietary military data and reverse-engineer UAV systems currently aiding Ukrainian defense forces.

The Cyber Trap: How Lazarus Infiltrated the Defense Sector

Lazarus’s latest campaign leaned heavily on its signature move—social engineering. Defense sector employees across Europe received what seemed like irresistible job offers. Hidden inside these fake recruitment emails were infected attachments and trojanized software—weapons disguised as opportunities.

ESET identified three main victims:

A metal engineering firm in Southeastern Europe.

An aircraft component manufacturer.

A Central European defense contractor.

All three incidents shared a crucial clue: a malicious dropper file called “DroneEXEHijackingLoader.dll.” This file wasn’t random. Its name revealed the operation’s target—drone technology. Once executed, it deployed ScoringMathTea, a powerful remote access trojan (RAT) capable of full system control, file theft, and remote command execution.

Originally discovered in 2022, ScoringMathTea has become one of Lazarus’s go-to tools for espionage, designed to spy silently and adapt to multiple systems. The malware integrates with legitimate software environments to evade suspicion, using DLL proxying and AES-128 or ChaCha20 encryption to hide its malicious activity.

Hidden in Plain Sight: The Technical Stealth

What makes this campaign remarkable is its use of open-source camouflage. Lazarus didn’t just send out malware—it embedded its code inside trusted open-source software hosted on GitHub, such as Notepad++ plugins, MuPDF Reader, and DirectX Wrappers. By doing this, they ensured the malware appeared legitimate during download and installation, bypassing many corporate security filters.

The attackers further enhanced stealth through tools like QuanPinLoader and BinMergeLoader, which communicated through Microsoft’s Graph API. This allowed them to blend malicious command-and-control (C2) traffic into regular corporate network activity. Crucially, no malicious payloads were written to disk, leaving minimal traces for forensic detection.

This blend of legitimate frameworks and encrypted communication paints Lazarus as one of the most disciplined APT groups in the world. Every step is designed to evade not only software defenses but also human suspicion.

The Geopolitical Chessboard: Why Drones Matter to Pyongyang

The targets weren’t random. Many of the victim companies supply components for UAVs operating over Ukraine, a critical area of modern warfare. For North Korea, closely aligned with Russia, this data is invaluable. As Pyongyang expands its domestic drone programs, access to European engineering blueprints and manufacturing techniques offers a technological leap it could never achieve legally.

Reports indicate North Korea has been reverse-engineering Western drone models such as the RQ-4 Global Hawk and MQ-9 Reaper. Stolen data could allow them to replicate sophisticated systems, enhance targeting accuracy, and even develop affordable combat UAVs for export to allied states or clients.

In essence, Lazarus isn’t just hacking for information—it’s fueling a military-industrial espionage pipeline, turning stolen code and designs into real weapons.

Human Error: The Weakest Link in Defense

Despite rising global awareness of Operation DreamJob, Lazarus continues to succeed. Why? Because even the best defense systems crumble against human curiosity. The hackers exploit a psychological weakness—our desire for better opportunities.

A single click on a fake job offer, and an entire corporate network can be compromised. This ongoing vulnerability emphasizes the need for stronger employee training, zero-trust verification systems, and behavioral monitoring. Defense firms, often fixated on hardware security, must now focus on human resilience too.

As cyber warfare increasingly blurs the line between espionage and sabotage, even one compromised employee could expose years of military innovation.

What Undercode Say:

The Lazarus Group’s DreamJob revival marks an evolution in cyber-espionage strategy. The operation isn’t about brute-force hacking; it’s about psychological infiltration and adaptive stealth. By masquerading as job recruiters, Lazarus bypasses traditional cybersecurity perimeters and attacks from the inside out.

From an analytical standpoint, this campaign demonstrates how APT groups now weaponize human trust as effectively as code. The choice of UAV targets reveals Pyongyang’s ambition to modernize its air reconnaissance and strike capabilities. As North Korea seeks parity with technologically advanced adversaries, cyber espionage becomes its most accessible route.

This also reflects a shifting doctrine in cyber warfare—the merging of state intelligence goals with criminal-level operational tactics. Lazarus operates like a hybrid between a spy agency and a cybercrime syndicate. Their approach is disciplined, yet opportunistic, always adapting to international conflicts and technology shifts.

The use of Microsoft Graph API for C2 communication is particularly strategic. By embedding malicious operations into a trusted cloud environment, Lazarus ensures that its signals are indistinguishable from legitimate enterprise traffic. This raises a worrying precedent: the weaponization of legitimate cloud services.

For defense contractors and governments, this means perimeter security alone is no longer enough. What’s required now is continuous network visibility, AI-driven anomaly detection, and proactive threat hunting to detect behavioral irregularities.

Strategically, Pyongyang’s espionage efforts fit into a broader pattern of resource-efficient warfare. Instead of developing billion-dollar R&D programs, it steals innovation from others. The drone intelligence Lazarus collects today could power North Korea’s export ambitions tomorrow, transforming cyber theft into geopolitical leverage.

For Europe, the implications are profound. These intrusions don’t only jeopardize military blueprints; they expose the continent’s supply chain dependencies, revealing how tightly defense innovation is interlinked.

Ultimately, this campaign serves as a stark reminder: cybersecurity is no longer a technical issue—it’s a national security imperative.

🔍 Fact Checker Results

✅ ESET confirmed the DreamJob campaign’s reemergence in March 2025.
✅ Lazarus Group is officially classified as a North Korean APT by multiple intelligence agencies.
✅ Technical analysis verified the use of “DroneEXEHijackingLoader.dll” and ScoringMathTea RAT in the attacks.

📊 Prediction

🚨 Expect Lazarus to expand its target base to aerospace subcontractors and AI-driven UAV analytics firms in late 2025.
🛰️ North Korea’s domestic drone capability will likely grow rapidly through 2026, aided by stolen European designs.
💡 Defense organizations that fail to integrate human-factor training and continuous monitoring could face more DreamJob-style breaches in the coming months.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon