ESET Uncovers North Korean Lazarus Group's Espionage Campaign Targeting European Defence and Drone Firms
23 October 2025
The European defence sector faces a new and highly sophisticated cyber threat as ESET's threat intelligence team has uncovered "Operation DreamJob," an ongoing campaign orchestrated by North Korea’s Lazarus Group, that is actively targeting leading defence contractors and drone technology firms operating in Europe. This campaign employs elaborate social engineering schemes – specifically, the dissemination of fraudulent job offers purportedly from prestigious defence organizations – as the initial vector to compromise sensitive targets within the European B2B defence environment.
According to ESET’s full report released on 23 October 2025, Lazarus executed targeted phishing attacks by issuing fake employment offers to key personnel within selected European defence and drone enterprises. These offers were designed to appear as legitimate recruitment communications and leveraged real job descriptions lifted from actual defence contractor job postings. Unsuspecting employees who engaged with these messages were prompted to download documents or links that embedded custom malware, providing the attackers with a covert channel into the firms’ digital infrastructure.
Once inside the targeted systems, Lazarus utilized advanced persistent threat (APT) tactics to escalate access and systematically exfiltrate proprietary data, including technical documentation related to unmanned aerial vehicles (UAVs), advanced sensor integration architectures, weapons systems networking, and other research and development files central to European military capability advancements. The group demonstrated sophisticated counter-intelligence approaches: evading endpoint detection, employing encrypted outbound communications to command-and-control servers, and leveraging the compromised credentials to explore internal networks undetected for prolonged periods.
This operation has already impacted several high-profile firms involved not only in UAV manufacturing but also in broader defence technology supply chains, potentially undermining the competitive position of European system integrators and technology providers. ESET’s analysts noted clear links between the stolen datasets and recent North Korean attempts to leapfrog indigenous research capabilities in autonomous systems and secure communications.
For B2B defence contractors, the incident signals a pronounced escalation in the nature of persistent cyber threats. The attackers’ focus on enterprise R&D repositories, executive email accounts, and procurement systems underscores the strategic objectives of both technology theft and disruption of ongoing and future tender processes. As a result, the attack is prompting urgent reviews of digital and physical access policies, multi-factor authentication deployment, workforce security training, and supply-chain cybersecurity integration across the European defence sector. Furthermore, this case highlights the need for greater pan-European intelligence-sharing regarding threat actor tactics, techniques, and procedures (TTPs).
Failure to address these coordinated cyber operations could lead to long-term erosion of proprietary advantage and critical infrastructure vulnerabilities especially among those operating in emerging and dual-use defence markets. As ESET’s report makes clear, only collective resilience-building, threat intelligence collaboration, and the implementation of robust incident response protocols will ensure the continued security and technological supremacy of European defence firms in this new cyber threat landscape.