Lazarus Attack on Spanish Aerospace Company Started with Messages from Phony Meta Recruiters

Stu Sjouwerman | Oct 2, 2023

aerospace cybersecurity attackA recent attack on an undisclosed Spanish aerospace company all started with messages to the company's employees that appeared to be coming from Meta recruiters, via LinkedIn Messaging. ESET researchers uncovered the attack and attributed it to the Lazarus group, particularly a campaign dubbed Operation DreamJob. This campaign by the Lazarus group was aimed at defense and aerospace companies with the goal of carrying out cyberespionage. 

Initial messages sent to the aerospace company's employees claimed to be from a recruiter for Meta. They started with a friendly tone from the very beginning, a tactic designed to get victims to let their guards down:

phony-Meta-recruiter-messages

Source: ESET

Subsequent messages to some victims included an attacker-provided, trojanized PDF viewer to view the full job offer, while others were encouraged to connect with a trojanized SSL/VPN client, being provided with an IP address and login details, under the guise of proving their C++ programming language abilities.

Two coding challenges were sent as a part of the supposed hiring process. The initial challenge consists of a straightforward project that displays the phrase "Hello, World!" while the second challenge prints a Fibonacci sequence - a series of numbers where each number is the sum of the two numbers that came before it. 

These "challenges" delivered malicious payloads to the victims, including a sophisticated remote access trojan (RAT) that ESET calls LightlessCan. This new RAT mimics a set of native Windows commands, allowing it to run its executions undetected. Lazarus also made sure the payload would only be encrypted on the specific victim's machine to avoid maximum exposure.

This isn't the first time we've seen employees get duped by cybercriminals posing as recruiters, and it won't be the last. New school security awareness training can help employees learn to recognize and fend off malicious activity designed to lure job-seekers.

KnowBe4 enables your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Access the World’s Largest Security Awareness Library

Explore over 1,000 interactive modules, videos, and games designed to sharpen user instincts and secure AI interactions. Get instant access to our Free Training Preview and find the perfect content to fortify your security culture.

Get Your Free Training Preview

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.