Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company
A Lazarus group cyberespionage campaign targeted a Spanish aerospace company by impersonating Meta recruiters on LinkedIn and sending trojanized coding challenges to employees. The attackers used spearphishing via LinkedIn Messaging to deliver malicious executables disguised as C++ programming tests. The attack employed DLL side-loading to deploy multiple payloads, including the NickelLoader downloader, a miniBlindingCan variant, and the advanced LightlessCan remote access trojan (RAT). LightlessCan features enhanced stealth and execution guardrails, representing a significant evolution over its predecessor BlindingCan. The campaign aimed to steal aerospace technology and know-how, aligning with North Korean strategic interests in missile development.
AI Analysis
Technical Summary
ESET researchers identified a Lazarus group attack against a Spanish aerospace company involving spearphishing through LinkedIn Messaging. Attackers masqueraded as Meta recruiters and sent trojanized coding challenges containing malicious executables. The attack chain used DLL side-loading to deliver payloads such as NickelLoader downloader, miniBlindingCan variant, and the sophisticated LightlessCan RAT, which supports 68 commands and mimics native Windows commands to evade detection. LightlessCan improves on BlindingCan by adding execution guardrails and enhanced stealth features. The campaign's objective was cyberespionage targeting aerospace technology consistent with North Korean missile development goals.
Potential Impact
The campaign enabled attackers to gain initial access to a targeted aerospace company via social engineering and spearphishing, leading to deployment of multiple malware tools capable of stealthy remote access and control. The advanced LightlessCan RAT allows extensive command execution while evading detection, facilitating espionage and theft of sensitive aerospace technology and intellectual property. This poses a medium-level threat to the confidentiality and integrity of targeted organizations' data and intellectual assets.
Mitigation Recommendations
No official patch or remediation is indicated for this campaign. Mitigation should focus on user awareness to recognize spearphishing attempts, especially those impersonating recruiters on professional networks like LinkedIn. Organizations should implement endpoint detection capable of identifying DLL side-loading and unusual command execution patterns. Monitoring for known Lazarus tools such as NickelLoader, BlindingCan variants, and LightlessCan is recommended. Since this is a targeted espionage campaign, tailored threat hunting and incident response are advised.
Indicators of Compromise
- ip: 178.251.26.65
- ip: 118.98.221.14
- ip: 50.192.28.29
- ip: 199.188.206.75
- domain: turnscor.com
- domain: barsaji.com.mx
- url: https://hurricanepub.com/include/include.php
- url: https://turnscor.com/wp-includes/contacts.php
- domain: hurricanepub.com
- url: http://mantis.quick.net.pl/library/securimage/index.php
- url: http://www.keewoom.co.kr/prod_img/201409/prod.php
- domain: mantis.quick.net.pl
- domain: www.keewoom.co.kr
- hash: 0f33ece7c32074520fbea46314d7d5ab9265ec52
- hash: 10bd3e6ba6a48d3f2e056c4f974d90549aed1b96
- hash: 247c5f59cffbaf099203f5ba3680f82a95c51e6e
- hash: 3007dda05ca8c7de85cd169f3773d43b1a009318
- hash: 38736ca46d7fc9b9e5c74d192eec26f951e45752
- hash: 8cb37fa97e936f45fa8ecd7eb5cfb68545810a22
- hash: c136dd71f45eaef3206bf5c03412195227d15f38
- hash: c273b244ea7dff20b1d6b1c7fd97f343201984b3
- hash: c7c6027abdced3093288ab75fab907c598e0237d
- hash: c830b895fb934291507e490280164cc4234929f0
- hash: e18b9743ec203ab49d3b57fed6df5a99061f80e0
- hash: e61672b23dbd03fe3b97ee469fa0895ed1f9185d
- hash: ebd3ef268c71a0ed11ae103aa745f1d8a63ddf13
- ip: 175.207.13.231
- ip: 185.51.65.233
- ip: 78.11.12.13
- ip: 89.187.86.214
- domain: kittimasszazs.hu
- domain: nrfm.lk
- domain: bug.restoroad.com
- domain: kerstpakketten.horesca-meppel.nl
- domain: www.radiographers.org
- url: http://barsaji.com.mx/src/recaptcha/index.php
- url: http://bug.restoroad.com/admin/view_status.php
- url: https://kerstpakketten.horesca-meppel.nl/wp-content/plugins/woocommerce/lib.php
- url: https://kittimasszazs.hu/images/virag.php
- url: https://nrfm.lk/wp-includes/SimplePie/content.php
- url: https://www.radiographers.org/aboutus/aboutus.php
- domain: kapata-arkeologi.kemdikbud.go.id
- url: https://kapata-arkeologi.kemdikbud.go.id/pages/payment/payment.php
Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company
Description
A Lazarus group cyberespionage campaign targeted a Spanish aerospace company by impersonating Meta recruiters on LinkedIn and sending trojanized coding challenges to employees. The attackers used spearphishing via LinkedIn Messaging to deliver malicious executables disguised as C++ programming tests. The attack employed DLL side-loading to deploy multiple payloads, including the NickelLoader downloader, a miniBlindingCan variant, and the advanced LightlessCan remote access trojan (RAT). LightlessCan features enhanced stealth and execution guardrails, representing a significant evolution over its predecessor BlindingCan. The campaign aimed to steal aerospace technology and know-how, aligning with North Korean strategic interests in missile development.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ESET researchers identified a Lazarus group attack against a Spanish aerospace company involving spearphishing through LinkedIn Messaging. Attackers masqueraded as Meta recruiters and sent trojanized coding challenges containing malicious executables. The attack chain used DLL side-loading to deliver payloads such as NickelLoader downloader, miniBlindingCan variant, and the sophisticated LightlessCan RAT, which supports 68 commands and mimics native Windows commands to evade detection. LightlessCan improves on BlindingCan by adding execution guardrails and enhanced stealth features. The campaign's objective was cyberespionage targeting aerospace technology consistent with North Korean missile development goals.
Potential Impact
The campaign enabled attackers to gain initial access to a targeted aerospace company via social engineering and spearphishing, leading to deployment of multiple malware tools capable of stealthy remote access and control. The advanced LightlessCan RAT allows extensive command execution while evading detection, facilitating espionage and theft of sensitive aerospace technology and intellectual property. This poses a medium-level threat to the confidentiality and integrity of targeted organizations' data and intellectual assets.
Defensive Guidance
No official patch or remediation is indicated for this campaign. Mitigation should focus on user awareness to recognize spearphishing attempts, especially those impersonating recruiters on professional networks like LinkedIn. Organizations should implement endpoint detection capable of identifying DLL side-loading and unusual command execution patterns. Monitoring for known Lazarus tools such as NickelLoader, BlindingCan variants, and LightlessCan is recommended. Since this is a targeted espionage campaign, tailored threat hunting and incident response are advised.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company"]
- Adversary
- Lazarus
- Pulse Id
- 6aadad46b23f435094676848
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip178.251.26.65 | — | |
ip118.98.221.14 | — | |
ip50.192.28.29 | — | |
ip199.188.206.75 | — | |
ip175.207.13.231 | — | |
ip185.51.65.233 | — | |
ip78.11.12.13 | — | |
ip89.187.86.214 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainturnscor.com | — | |
domainbarsaji.com.mx | — | |
domainhurricanepub.com | — | |
domainmantis.quick.net.pl | — | |
domainwww.keewoom.co.kr | — | |
domainkittimasszazs.hu | — | |
domainnrfm.lk | — | |
domainbug.restoroad.com | — | |
domainkerstpakketten.horesca-meppel.nl | — | |
domainwww.radiographers.org | — | |
domainkapata-arkeologi.kemdikbud.go.id | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://hurricanepub.com/include/include.php | — | |
urlhttps://turnscor.com/wp-includes/contacts.php | — | |
urlhttp://mantis.quick.net.pl/library/securimage/index.php | — | |
urlhttp://www.keewoom.co.kr/prod_img/201409/prod.php | — | |
urlhttp://barsaji.com.mx/src/recaptcha/index.php | — | |
urlhttp://bug.restoroad.com/admin/view_status.php | — | |
urlhttps://kerstpakketten.horesca-meppel.nl/wp-content/plugins/woocommerce/lib.php | — | |
urlhttps://kittimasszazs.hu/images/virag.php | — | |
urlhttps://nrfm.lk/wp-includes/SimplePie/content.php | — | |
urlhttps://www.radiographers.org/aboutus/aboutus.php | — | |
urlhttps://kapata-arkeologi.kemdikbud.go.id/pages/payment/payment.php | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash0f33ece7c32074520fbea46314d7d5ab9265ec52 | — | |
hash10bd3e6ba6a48d3f2e056c4f974d90549aed1b96 | — | |
hash247c5f59cffbaf099203f5ba3680f82a95c51e6e | — | |
hash3007dda05ca8c7de85cd169f3773d43b1a009318 | — | |
hash38736ca46d7fc9b9e5c74d192eec26f951e45752 | — | |
hash8cb37fa97e936f45fa8ecd7eb5cfb68545810a22 | — | |
hashc136dd71f45eaef3206bf5c03412195227d15f38 | — | |
hashc273b244ea7dff20b1d6b1c7fd97f343201984b3 | — | |
hashc7c6027abdced3093288ab75fab907c598e0237d | — | |
hashc830b895fb934291507e490280164cc4234929f0 | — | |
hashe18b9743ec203ab49d3b57fed6df5a99061f80e0 | — | |
hashe61672b23dbd03fe3b97ee469fa0895ed1f9185d | — | |
hashebd3ef268c71a0ed11ae103aa745f1d8a63ddf13 | — |
Threat ID: 6ab0eeed55bf5e2cf599881c
Added to database: 09/21/2026, 08:46:37 UTC
Last enriched: 09/21/2026, 09:01:46 UTC
Last updated: 09/21/2026, 18:45:54 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.