QuanPinLoader is a loader observed by ESET in a 2025 wave of Operation DreamJob activity attributed with high confidence to the North Korea-aligned Lazarus group. In the reported campaign, Lazarus targeted multiple European defense-sector organizations, including companies associated with UAV and aircraft-component production, using fake recruiter/job-offer social engineering. Victims were lured with decoy job-description documents and trojanized software, while multi-stage droppers/loaders/downloaders were used to deliver the main payload, ScoringMathTea RAT.
ESET identified QuanPinLoader as a loader likely based on the open-source Sample IME project. Reported identifying traits include use of a Mandarin Chinese symbol (样) as an icon and the presence of the string "SampleIMESimplifiedQuanPin.txt". Within the broader DreamJob execution chain, loaders were described as decrypting later-stage payloads using AES-128 or ChaCha20 and loading them directly in memory via MemoryModule routines, with the main payload not present on disk in unencrypted form in observed cases. QuanPinLoader was mentioned alongside other Lazarus tooling used in the same campaign, including trojanized MuPDF and TightVNC components, a libpcre-based loader, DirectX-wrapper-based loaders, BinMergeLoader, trojanized WinMerge plugins, and trojanized Notepad++ plugins.
The campaign’s ultimate payload was ScoringMathTea, a RAT providing full control of compromised systems and supporting roughly 40 commands, including file and process manipulation, system information collection, TCP/network communication, and command execution. ESET assessed the likely objective of the campaign as cyberespionage and theft of proprietary information and manufacturing know-how, with notable interest in UAV/drone-related technology. VirusTotal submissions associated with this activity reportedly included a QuanPinLoader sample submitted from Italy in April/June 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Early-stage loader/downloader used in Operation DreamJob to stage and load subsequent payloads (main-stage implants) in the infection chain.
Loader (likely based on the Sample IME open-source project) used in early stages to decrypt and load subsequent stages in memory; associated with Lazarus/Operation DreamJob toolchains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.