Skip to main content

Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company

0
Medium
Published: 09/18/2026 (09/18/2026, 21:29:42 UTC)
Source: AlienVault OTX General

Description

A Lazarus group cyberespionage campaign targeted a Spanish aerospace company by impersonating Meta recruiters on LinkedIn and sending trojanized coding challenges to employees. The attackers used spearphishing via LinkedIn Messaging to deliver malicious executables disguised as C++ programming tests. The attack employed DLL side-loading to deploy multiple payloads, including the NickelLoader downloader, a miniBlindingCan variant, and the advanced LightlessCan remote access trojan (RAT). LightlessCan features enhanced stealth and execution guardrails, representing a significant evolution over its predecessor BlindingCan. The campaign aimed to steal aerospace technology and know-how, aligning with North Korean strategic interests in missile development.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/21/2026, 09:01:46 UTC

Technical Analysis

ESET researchers identified a Lazarus group attack against a Spanish aerospace company involving spearphishing through LinkedIn Messaging. Attackers masqueraded as Meta recruiters and sent trojanized coding challenges containing malicious executables. The attack chain used DLL side-loading to deliver payloads such as NickelLoader downloader, miniBlindingCan variant, and the sophisticated LightlessCan RAT, which supports 68 commands and mimics native Windows commands to evade detection. LightlessCan improves on BlindingCan by adding execution guardrails and enhanced stealth features. The campaign's objective was cyberespionage targeting aerospace technology consistent with North Korean missile development goals.

Potential Impact

The campaign enabled attackers to gain initial access to a targeted aerospace company via social engineering and spearphishing, leading to deployment of multiple malware tools capable of stealthy remote access and control. The advanced LightlessCan RAT allows extensive command execution while evading detection, facilitating espionage and theft of sensitive aerospace technology and intellectual property. This poses a medium-level threat to the confidentiality and integrity of targeted organizations' data and intellectual assets.

Defensive Guidance

No official patch or remediation is indicated for this campaign. Mitigation should focus on user awareness to recognize spearphishing attempts, especially those impersonating recruiters on professional networks like LinkedIn. Organizations should implement endpoint detection capable of identifying DLL side-loading and unusual command execution patterns. Monitoring for known Lazarus tools such as NickelLoader, BlindingCan variants, and LightlessCan is recommended. Since this is a targeted espionage campaign, tailored threat hunting and incident response are advised.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company"]
Adversary
Lazarus
Pulse Id
6aadad46b23f435094676848

Indicators of Compromise

Ip

ValueDescriptionCopy
ip178.251.26.65
ip118.98.221.14
ip50.192.28.29
ip199.188.206.75
ip175.207.13.231
ip185.51.65.233
ip78.11.12.13
ip89.187.86.214

Domain

ValueDescriptionCopy
domainturnscor.com
domainbarsaji.com.mx
domainhurricanepub.com
domainmantis.quick.net.pl
domainwww.keewoom.co.kr
domainkittimasszazs.hu
domainnrfm.lk
domainbug.restoroad.com
domainkerstpakketten.horesca-meppel.nl
domainwww.radiographers.org
domainkapata-arkeologi.kemdikbud.go.id

Url

ValueDescriptionCopy
urlhttps://hurricanepub.com/include/include.php
urlhttps://turnscor.com/wp-includes/contacts.php
urlhttp://mantis.quick.net.pl/library/securimage/index.php
urlhttp://www.keewoom.co.kr/prod_img/201409/prod.php
urlhttp://barsaji.com.mx/src/recaptcha/index.php
urlhttp://bug.restoroad.com/admin/view_status.php
urlhttps://kerstpakketten.horesca-meppel.nl/wp-content/plugins/woocommerce/lib.php
urlhttps://kittimasszazs.hu/images/virag.php
urlhttps://nrfm.lk/wp-includes/SimplePie/content.php
urlhttps://www.radiographers.org/aboutus/aboutus.php
urlhttps://kapata-arkeologi.kemdikbud.go.id/pages/payment/payment.php

Hash

ValueDescriptionCopy
hash0f33ece7c32074520fbea46314d7d5ab9265ec52
hash10bd3e6ba6a48d3f2e056c4f974d90549aed1b96
hash247c5f59cffbaf099203f5ba3680f82a95c51e6e
hash3007dda05ca8c7de85cd169f3773d43b1a009318
hash38736ca46d7fc9b9e5c74d192eec26f951e45752
hash8cb37fa97e936f45fa8ecd7eb5cfb68545810a22
hashc136dd71f45eaef3206bf5c03412195227d15f38
hashc273b244ea7dff20b1d6b1c7fd97f343201984b3
hashc7c6027abdced3093288ab75fab907c598e0237d
hashc830b895fb934291507e490280164cc4234929f0
hashe18b9743ec203ab49d3b57fed6df5a99061f80e0
hashe61672b23dbd03fe3b97ee469fa0895ed1f9185d
hashebd3ef268c71a0ed11ae103aa745f1d8a63ddf13

Threat ID: 6ab0eeed55bf5e2cf599881c

Added to database: 09/21/2026, 08:46:37 UTC

Last enriched: 09/21/2026, 09:01:46 UTC

Last updated: 09/21/2026, 18:45:54 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses