Close Menu
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

GentleKiller Ransomware Bypasses Security by Targeting Vulnerable Drivers and Disabling Over 400 EDR Processes

June 21, 2026

Staff Stories Spotlight: Celebrating Cybersecurity Awareness Month 2024

June 20, 2026

Hackers Exploit Gravity SMTP Plugin to Leverage API Key Exposure

June 20, 2026
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cybercrime and Ransomware
  • Emerging Tech
  • Threat Intelligence
  • Expert Insights
  • Careers and Learning
  • Compliance
Home » Lazarus Group Targets European Drone Manufacturing Secrets
Cyber Updates

Lazarus Group Targets European Drone Manufacturing Secrets

Staff WriterBy Staff WriterOctober 23, 2025Updated:October 25, 2025No Comments5 Mins Read16 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

Quick Takeaways

  1. Targeting Drone Manufacturing: North Korea’s Lazarus Group is focused on stealing proprietary information from European drone manufacturers to enhance its domestic drone capabilities.

  2. Specific Campaign Details: ESET researchers identified attacks on at least three organizations in Central and Southeastern Europe, all related to military drone production, tying into North Korea’s interest in UAV technology.

  3. Malware Utilization: The group’s primary weapon, ScoringMathTea, is a remote access Trojan enabling full control of infected systems, showing little evolution since its introduction but highlighting operational simplicity and stability.

  4. Strategic Cyber Tactics: Lazarus employs decoy job-themed documents to infiltrate systems while leveraging compromised open-source software to evade detection, underscoring the importance of cybersecurity awareness in sensitive sectors.

[gptAs a technology journalist, write a short news story divided in two subheadings, at 12th grade reading level about ‘Lazarus Group Hunts European Drone Manufacturing Data’in short sentences using transition words, in an informative and explanatory tone, from the perspective of an insightful Tech News Editor, ensure clarity, consistency, and accessibility. Use concise, factual language and avoid jargon that may confuse readers. Maintain a neutral yet engaging tone to provide balanced perspectives on practicality, possible widespread adoption, and contribution to the human journey. Avoid passive voice. The article should provide relatable insights based on the following information ‘

North Korea’s relentless Lazarus Group is at it again, this time targeting drone manufacturers in Europe to steal proprietary information and manufacturing know-how for Pyongyang.

ESET researchers tracking the campaign have identified at least three organizations Lazarus has struck so far, all located in Central and Southeastern Europe. The targeted organizations manufacture a range of military equipment, including unmanned aerial vehicles (UAVs, aka drones), some of which Ukraine is using in its war against Russia.

Aligned with North Korean Interests

The attacks align with North Korea’s intensifying efforts to scale up its domestic drone program using proprietary data stolen from elsewhere. “These entities are involved in the production of types of materiel that North Korea also manufactures domestically, and for which it might be hoping to perfect its own designs and processes,” ESET disclosed in a report this week. “The interest in UAV-related know-how is notable, as it echoes recent media reports indicating that Pyongyang is investing heavily in domestic drone manufacturing capabilities.”

ESET has assessed the drone data theft campaign to be the latest iteration of “Operation DreamJob,” where Lazarus actors have been using job-themed decoy documents to lure victims into installing malware on their systems. The threat actor has used the same ploy in cyberespionage attacks on the chemical sector, information technology companies, financial services, software developers, and others.

Related:MuddyWater Targets 100+ Gov Entities in MEA With Phoenix Backdoor

The drone campaign’s primary payload is ScoringMathTea, a remote access Trojan (RAT) that gives Lazarus actors attackers interactive control over infected machines. The threat actor has been using the post-compromise RAT since at least 2022, when it first surfaced on VirusTotal masquerading as an Airbus-themed job lure. ScoringMathTea supports some 40 commands, including those that allow Lazarus actors to manipulate files and processes, conduct system reconnaissance, and download and execute additional malicious payloads on compromised systems.

A Stable, Sophisticated Weapon

ScoringMathTea has been Lazarus’s primary payload in Operation DreamJob campaigns, according to ESET. It surfaced in attacks on an Indian technology company in January 2023, a Polish defense firm in March 2023, a British industrial automation company in October 2023, and an Italian aerospace company in last month.

Surprisingly, ScoringMathTea itself has remained largely unchanged since it was first spotted, says Peter Kalnai, senior malware researcher at ESET, in comments to Dark Reading. “ScoringMathTea RAT shows no readily apparent changes, with its set of features remaining almost identical,” since the beginning.

Related:Asian Nations Ramp Up Pressure on Cybercrime ‘Scam Factories’

That suggests that the threat actor favors operational simplicity and stability over sophistication, something that Lazarus has demonstrated with some of its other RATs, such as LightlessCan, he says. “Moreover, ScoringMathTea is likely not the final stage in the execution chain, as its capabilities are extensible through the loading of additional DLLs, which effectively function as plug-ins.”

The most significant change is Lazarus group’s use of new libraries designed for DLL proxying and the use of compromised open source projects on GitHub to hide their malware. Kalnai says ESET found no evidence that Lazarus actors had compromised any GitHub accounts to Trojanize projects. Instead, the attackers selected a few less popular open source projects, such as plug-ins for Notepad++ and WinMerge, modified the code locally, and deployed them to target systems in an attempt to bypass standard detection mechanisms.

Campaigns like these highlight why threat awareness among employees is key, Kalnai says. Another aspect is general policies regarding cyberattacks in sensitive sectors. “Currently, even when governing bodies issue security advisories, private companies are under no obligation to review or comply with the recommendations,” he says. “Furthermore, the severity of a security incident needs to rise to a certain threshold before a company is obligated to report it to authorities. Otherwise, the company does not even have to share the results of the incident response process.”

Related:‘PassiveNeuron’ Cyber Spies Target Orgs With Custom Malware

‘. Do not end the article by saying In Conclusion or In Summary. Do not include names or provide a placeholder of authors or source. Make Sure the subheadings are in between html tags of

[/gpt3]

Expand Your Tech Knowledge

Stay informed on the revolutionary breakthroughs in Quantum Computing research.

Explore past and present digital transformations on the Internet Archive.

CyberRisk-V1

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleBeyond Boundaries: The Shift from Perimeter Tools
Next Article Mastering Secrets Sprawl: Streamlined Security for Modern Environments
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

Bridging the Critical Confidence Gap in Enterprise AI Security

June 16, 2026

Legal Industry VPNs: Falling to Modern Threats

June 15, 2026

Closing the Gap: The Rising Threat of Third-Party Privileged Access

June 14, 2026

Comments are closed.

Latest Posts

GentleKiller Ransomware Bypasses Security by Targeting Vulnerable Drivers and Disabling Over 400 EDR Processes

June 21, 2026

Threat Actor Deploys Advanced EDR-Crushing Tools in Ransomware Platform

June 19, 2026

CISA Flags LiteSpeed cPanel Plugin Vulnerability Amid Active Exploitation

June 19, 2026

INC Ransomware Launches Rust-Based Attacks on Windows, Linux, and ESXi

June 19, 2026
Don't Miss

Bridging the Critical Confidence Gap in Enterprise AI Security

By Staff WriterJune 16, 2026

Summary Points Current AI security testing methods, like tabletop exercises, fail to reveal how AI…

Legal Industry VPNs: Falling to Modern Threats

June 15, 2026

Closing the Gap: The Rising Threat of Third-Party Privileged Access

June 14, 2026

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Recent Posts

  • GentleKiller Ransomware Bypasses Security by Targeting Vulnerable Drivers and Disabling Over 400 EDR Processes
  • Staff Stories Spotlight: Celebrating Cybersecurity Awareness Month 2024
  • Hackers Exploit Gravity SMTP Plugin to Leverage API Key Exposure
  • Threat Actor Deploys Advanced EDR-Crushing Tools in Ransomware Platform
  • Fortinet VPN vulnerability exploited for remote access compromise
About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

GentleKiller Ransomware Bypasses Security by Targeting Vulnerable Drivers and Disabling Over 400 EDR Processes

June 21, 2026

Staff Stories Spotlight: Celebrating Cybersecurity Awareness Month 2024

June 20, 2026

Hackers Exploit Gravity SMTP Plugin to Leverage API Key Exposure

June 20, 2026
Most Popular

Protecting MCP Security: Defeating Prompt Injection & Tool Poisoning

January 30, 202633 Views

Unlock the Power of Free WormGPT: Harnessing DeepSeek, Gemini, and Kimi-K2 AI Models

November 27, 202530 Views

The New Face of DDoS is Impacted by AI

August 4, 202528 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025

Categories

  • Compliance
  • Cyber Updates
  • Cybercrime and Ransomware
  • Editor's pick
  • Emerging Tech
  • Events
  • Featured
  • Insights
  • Most Read
  • Threat Intelligence
  • Uncategorized
© 2026 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.