Operation DreamJob Targets European UAV and Defense Manufacturers: Lazarus Deploys ScoringMathTea via Trojanized Open-Source Tools

ESET researchers documented in a report published by ESET Research a new wave of Lazarus Group's Operation DreamJob campaign targeting three European defense sector companies — including entities involved in UAV development — between late March and September 2025. The campaign deployed ScoringMathTea RAT via trojanized open-source applications and fake job offer lures, with a dropper bearing the internal DLL name DroneEXEHijackingLoader.dll providing unusually direct evidence of the campaign's UAV intelligence-collection focus.

Targets and Geopolitical Context

Three European companies were targeted: a metal engineering company in Southeastern Europe, an aircraft components manufacturer in Central Europe, and a defense company in Central Europe. At least two are demonstrably involved in UAV development — one manufacturing critical drone components and another engaged in UAV software design. Several of these organizations produce equipment currently deployed in Ukraine. ESET assesses the campaign was likely aimed at stealing proprietary UAV manufacturing know-how, coinciding with documented North Korean efforts to scale its domestic drone program — including reported Russian assistance to produce a domestic Shahed-derivative and development of exportable low-cost attack UAVs. North Korea's flagship reconnaissance drone (Saetbyol-4) and combat drone (Saetbyol-9) visually replicate the Northrop Grumman RQ-4 Global Hawk and General Atomics MQ-9 Reaper respectively, underscoring the regime's reliance on reverse engineering and intellectual property theft for UAV development.

Initial Access: Fake Job Offers and Trojanized Open-Source Projects

Consistent with Operation DreamJob's defining social engineering methodology, victims received decoy documents presenting lucrative job descriptions alongside a trojanized PDF reader to open them. The attackers trojanized multiple open-source GitHub projects to serve as droppers, loaders, and downloaders, with malicious loading routines embedded into legitimate codebases for evasion via DLL proxying. Projects trojanized in 2025 include TightVNC Viewer, MuPDF reader, libpcre v8.45, a Sample IME-based input method editor (QuanPinLoader), DirectX Wrappers, WinMerge plugins DisplayBinaryFiles and HideFirstLetter (collectively BinMergeLoader), and Notepad++ plugins NPPHexEditor v10.0.0 and ComparePlus v1.1.0. The ComparePlus dropper PDB path contains the Korean word for "stable" (안정화), indicating tested and reliable code.

All droppers carry two types of exports: DLL proxying functions to avoid breaking legitimate application execution, and malicious functions. Loaders decrypt payloads using AES-128 or ChaCha20 and load them directly into memory via the MemoryModule library. BinMergeLoader additionally leverages the Microsoft Graph API with Microsoft API tokens for C2 communication, analogous to the MISTPEN malware reported by Mandiant.

ScoringMathTea: Three Years as Operation DreamJob's Flagship RAT

The primary payload in all three 2025 cases is ScoringMathTea — a complex RAT supporting approximately 40 commands, named for an early C2 domain and tracked by Microsoft as ForestTiger. First observed in VirusTotal submissions from Portugal and Germany in October 2022 with an Airbus-themed job offer dropper, it has since appeared in confirmed attacks against an Indian technology company (January 2023), a Polish defense company (March 2023), a British industrial automation company (October 2023), and an Italian aerospace company (September 2025). Its capabilities cover file and process manipulation, system information collection, configuration exchange, TCP connection establishment, and local command or payload execution. The RAT communicates via compromised servers, with C2 infrastructure typically hosted in WordPress theme or plugin directories. ScoringMathTea is never written to disk in unencrypted form — the loader chain always decrypts it directly into memory before execution.

The DroneEXEHijackingLoader: Campaign Intent Embedded in the Binary

One dropper (SHA-1: 03D9B8F0FCF9173D2964CE7173D21E681DFA8DA4) carries the internal DLL name DroneEXEHijackingLoader.dll — disguised as a Windows Web Services Runtime library for DLL side-loading. ESET assesses the "drone" substring designates both the UAV target domain and an internal campaign label, constituting unusually direct operational evidence of the campaign's intelligence collection objective embedded within the malware itself. The naming mirrors a pattern also seen in Operation DreamJob's prior targeting of Spanish and Polish aerospace companies, where ScoringMathTea deployments followed similar lure-document and trojanized-plugin delivery chains.

Read the full analysis on IntelFusions