Skip to main content

Threats Tagged 'binmergeloader'

View all threats tagged with 'binmergeloader'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: binmergeloader

Threats Tagged 'binmergeloader'

Click on any threat for detailed analysis and mitigation recommendations

Operation DreamJob is a cyberespionage campaign by the North Korea-aligned Lazarus group targeting European defense companies specializing in UAV technology. The attackers use social engineering and trojanized open-source software to deliver a sophisticated malware toolset including ScoringMathTea RAT and BinMergeLoader. The campaign aims to steal intellectual property and manufacturing knowledge to support North Korea's drone program. Attack techniques involve multiple stages with droppers, loaders, and downloaders, exploiting user interaction and system reconnaissance. The threat poses a medium severity risk due to targeted espionage with potential long-term strategic impact on defense capabilities. European UAV manufacturers and defense contractors are primary targets, especially in countries with significant aerospace industries. Mitigation requires enhanced supply chain security, strict validation of open-source software, user training against social engineering, and robust endpoint detection. Countries like Germany, France, Italy, and the UK are most likely affected given their UAV sector prominence and defense industry size. The campaign does not require zero-day exploits but leverages social engineering and trojanized software, increasing the risk of successful infiltration. Defenders should prioritize monitoring for known malware components and suspicious network activity related to this campaign.

Join the discussion

ESET researchers have uncovered a new instance of Operation DreamJob, a campaign attributed to the North Korea-aligned Lazarus group, targeting European defense companies involved in UAV technology. The attacks align with North Korea's efforts to enhance its drone program, likely aiming to steal proprietary information and manufacturing know-how. The campaign uses social engineering tactics, trojanized open-source projects, and deploys the ScoringMathTea RAT. The attackers' toolset includes various droppers, loaders, and downloaders, with a focus on UAV-related targets. This activity highlights the ongoing threat posed by Lazarus and North Korea's interest in advancing its drone capabilities through cyberespionage.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: binmergeloader
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses