Lazarus hackers spying on Central European defence industry

SECURITYLazarus hackers spying on Central European defence industry
- Advertisement -Translation agency in Poland – professional language servicesTranslation agency in Poland – professional language services

Cybercriminals from North Korea’s Lazarus Group have been caught spying on companies within the defence sector in Central Europe, according to new findings from ESET researchers. The affected organisations manufacture various types of military equipment — including drones and critical components — many of which are currently being used in Ukraine as part of military aid provided by European countries.

By infecting employees’ computers, the attackers attempted to steal information on the technology used to manufacture drones. This has raised concerns over the security of Poland’s defence industry, which is currently developing its own advanced drone capabilities — and has previously been targeted by Lazarus.


Espionage as part of North Korea’s wider geopolitical strategy

The Lazarus Group — backed by the North Korean state — continues to conduct cyber operations against European countries that support Ukraine. ESET researchers confirmed that the most recent attacks were highly targeted at the defence industry, particularly drone manufacturers. The campaign affected at least three companies in Central and Southeastern Europe, with the primary objective being the theft of confidential information and technical know-how — directly aligning with reports of North Korea intensifying its drone development programme.

In late September, North Korean leader Kim Jong-un publicly expressed satisfaction with recent combat drone tests, emphasising that drones are becoming a primary tool in modern warfare, making their development the country’s top strategic priority.

“We found evidence that one of the compromised entities is part of the supply chain for advanced single-rotor drones — essentially unmanned helicopters. This is a category of aircraft that Pyongyang is actively developing but has so far failed to militarise,” said Peter Kálnai, the ESET researcher who identified and analysed the attacks.

Historically, North Korea has heavily relied on foreign technologies and intellectual property theft to advance its drone programmes. Recent intelligence reports indicate that its flagship reconnaissance and combat drones — Saetbyol-4 and Saetbyol-9 — bear striking resemblance to their U.S. equivalents: the RQ-4 Global Hawk and MQ-9 Reaper.


“Operation Dream Job” — a new phase of an ongoing cyber campaign

According to ESET, these newly uncovered espionage operations represent a continuation of the campaign known as “Operation Dream Job.”

“The attackers rely heavily on social engineering — typically through attractive but fake job offers. The victim receives a carefully crafted job description along with the ‘required tools’ to open the file. These tools contain an embedded Remote Access Trojan (RAT), which gives attackers full control over the infected device,” explains Beniamin Szczepankiewicz, cybersecurity expert at ESET.

A similar version of this malware was detected in 2023 during an attack on a Polish defence company — evidence that Poland remains a direct target for Lazarus.


North Korean involvement extends beyond cyberspace

Lazarus’ cyber offensive may be closely tied to the war in Ukraine and North Korea’s growing support for Russia’s military operations. The three organisations identified by ESET produce military equipment — including drones — currently being deployed in Ukraine as part of Europe’s aid.

CNN recently reported that 11,000 North Korean troops are already supporting Russia, with plans to increase the number by another 25,000–30,000.[1]

Furthermore, the UK-based investigative group Conflict Armament Research (CAR) confirmed that North Korean ammunition was found after a recent drone strike on Kherson.[2]


Lazarus — one of the world’s most aggressive cyber groups

The attacks against Europe’s defence industry are systematic, carried out by advanced persistent threat (APT) groups, focused on government entities, defence suppliers and strategic industries. Their objectives include economic and political espionage, disruption, and disinformation.

Lazarus is one of the world’s most active and dangerous actors. According to ESET data[3], North Korean APT groups account for 14% of all global APT activity, ranking third after China (40.1%) and Russia (25.7%).

Lazarus has been active since at least 2009 and is responsible for major cyberattacks including the Sony Pictures hack and the infamous WannaCry ransomware outbreak in 2017, which infected over 200,000 computers across more than 100 countries.


[1] https://edition.cnn.com/2025/07/02/europe/north-korea-troops-russia-ukraine-intl-cmd
[2] https://edition.cnn.com/2025/10/17/europe/north-korea-submunition-russia-ukraine-intl
[3] https://web-assets.eset.com/fileadmin/ESET/US/B2B_Resource_centre/reports/APT_Activity_Report_Q4_2024-Q1_2025.pdf

Source: https://ceo.com.pl/cyberprzestepcy-z-korei-polnocnej-ze-wsparciem-dla-rosji-grupa-lazarus-atakuje-firmy-zbrojeniowe-dostarczajace-drony-ukrainie-54425

Check out our other content
Related Articles
The Latest Articles