The Containment Era is here. →Explore

Executive Summary

In March 2023, the Lazarus Group—an advanced persistent threat attributed to North Korea—successfully targeted three European companies in the defense sector involved in drone development. Leveraging Operation DreamJob, the attackers used social engineering tactics, including fraudulent job offers and a trojanized PDF reader, to gain initial access via phishing emails. The deployment of the ScoringMathTea remote access trojan enabled complete control over compromised systems, potentially allowing sensitive data exfiltration related to unmanned aerial vehicle (UAV) technology and manufacturing know-how. ESET researchers linked the attack to ongoing North Korean efforts to bolster domestic drone capabilities and noted the victims' support of military deployments in Ukraine.

The incident exemplifies the persistent and adaptive nature of sophisticated state-linked cyber-espionage campaigns targeting high-value defense technologies. As strategic competition and armed conflicts persist, such tactics have become more prevalent against organizations with intellectual property critical to national security.

Why This Matters Now

This attack highlights the ongoing and urgent risk of nation-state threats targeting defense supply chains, especially entities involved in drone and aerospace innovation. With geopolitical tensions rising, the exposure of advanced manufacturing knowledge increases risks not just to affected companies but also to allied military operations and national security ecosystems.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident underscored gaps in phishing resistance, endpoint security, and east-west traffic monitoring, fundamental to NIST, PCI, and HIPAA-aligned controls.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Comprehensive CNSF controls—such as zero trust segmentation, east-west traffic security, egress policy enforcement, and threat detection—could have blocked, contained, or rapidly detected this multi-stage attack. Segmenting workloads, controlling lateral movement, and tightly monitoring outbound flows would have severely limited Lazarus group’s ability to escalate privileges, pivot internally, and exfiltrate sensitive drone data.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Phishing-based activity and new malware execution would be rapidly detected.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Restricts privilege escalation scope by limiting access based on identity and microsegmentation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement attempts are blocked or logged for action by enforcing workload-to-workload security policies.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Known malicious C2 traffic is blocked and/or alerted on at the network edge.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts are blocked or flagged by restricting outbound traffic to authorized domains and protocols.

Impact (Mitigations)

Accelerated detection and incident response minimized impact to critical workloads.

Impact at a Glance

Affected Business Functions

  • Research and Development
  • Intellectual Property Management
  • Supply Chain Operations
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of proprietary drone design schematics, manufacturing processes, and software source code.

Recommended Actions

  • Implement zero trust segmentation and workload-level access policies to tightly constrain lateral attacker movement.
  • Deploy advanced threat detection with behavioral anomaly response to surface early stages of phishing and remote access tooling.
  • Enforce strict east-west and egress controls, including policy-driven outbound restrictions and real-time monitoring for unusual data transfers.
  • Leverage inline IPS and signature-based inspection at network perimeters and within cloud fabrics to block RAT C2 and malware propagation.
  • Enhance multicloud visibility and centralized incident response to detect, investigate, and contain attacks targeting sensitive intellectual property assets.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image