North Korea's Lazarus Group conducted a cyberespionage campaign against multiple European defense contractors specializing in drone and unmanned aerial vehicle (UAV) technology. ESET researchers identified at least three organizations in Central and Southeastern Europe that were targeted, with the attackers using sophisticated social engineering tactics, including fake job offers, to gain initial access. The campaign, assessed as a new wave of Operation DreamJob, aimed to steal proprietary manufacturing data and sensitive know-how, aligning with North Korea's efforts to advance its domestic drone program.
The attackers deployed a remote-access trojan (RAT) known as ScoringMathTea after compromising victims, granting them control over infected systems and facilitating data exfiltration. The targeted companies produce military equipment, some of which is being used in Ukraine, suggesting the operation may have also sought intelligence on Western-made weapons systems deployed in the ongoing conflict. The campaign highlights Lazarus Group's continued use of job-themed lures and its strategic focus on acquiring advanced defense technologies for Pyongyang's military ambitions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
As part of its public reporting, ESET released indicators of compromise covering malware components and domains associated with the Lazarus operation to help defenders detect related activity.
On October 23, 2025, ESET disclosed and attributed the campaign to North Korea's Lazarus Group as a new iteration of Operation DreamJob targeting European drone and defense manufacturers. The report described the espionage objective, victim profile, malware, and evasion techniques.
After initial compromise, Lazarus deployed multi-stage tooling including ScoringMathTea RAT and, in some cases, BinMergeLoader (MISTPEN), giving operators interactive remote control, reconnaissance capability, and a path to data theft and follow-on payload delivery.
To gain access, Lazarus used fake job offers, trojanized PDF reader documents, and modified open-source applications, then employed DLL sideloading/proxying and in-memory decryption to load malware while evading detection.
During the 2025 campaign, Lazarus compromised at least three defense-sector organizations in Central and Southeastern Europe, including companies involved in UAV development and manufacturers whose equipment is used in Ukraine.
Beginning in March 2025, Lazarus launched a new Operation DreamJob wave targeting European defense and drone-related companies with fake recruitment lures. The campaign focused on stealing proprietary manufacturing data and know-how, especially related to UAV technology.
ESET noted that the ScoringMathTea remote access trojan used in this campaign was first seen in 2022 and has remained a core Lazarus payload with only limited changes over time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcecsoonline.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourcecyberscoop.com
Open sourcesecurityaffairs.com
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.