216.73.217.22

Gotta fly: Targeting the UAV sector

· Published 09/11/2025 04:31 · Modified 10/11/2025 12:06

Export JSON

Essential information

Published
09/11/2025 04:31
Modified
10/11/2025 12:06
Tags
2025-11-09 binmergeloader cyberespionage defense industry north korea operation dreamjob quanpinloader scoringmathtea social engineering trojanized software uav
Related entities
1 intrusion sets (apt), 12 techniques (mitre), 3 malware, 3 others

Description

ESET researchers have uncovered a new instance of , a campaign attributed to the -aligned Lazarus group. The attackers targeted European companies in the , particularly those involved in unmanned aerial vehicle () technology. The campaign aligns with 's efforts to enhance its drone program, likely aiming to steal proprietary information and manufacturing know-how. The attackers used techniques, trojanized open-source projects, and deployed the RAT. The toolset included various droppers, loaders, and downloaders, with execution chains delivering and . The campaign's focus on technology reflects 's investment in drone manufacturing and its reliance on reverse engineering and intellectual property theft.

External references