#ScoringMathTea
Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities
Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities
cybersecuritynews.com
November 18, 2025 at 10:39 AM
"Nation-State Actor’s Arsenal: An In-Depth Look at Lazarus’ ScoringMathTea" published by 0x0d4y. #Lazarus, #ScoringMathTea, #DPRK, #CTI https://0x0d4y.blog/arsenal-analysis-of-a-nation-state-actor-an-in-depth-look-at-lazarus-scoringmathtea/
November 18, 2025 at 1:30 PM
Alert: The Lazarus Group has unveiled ScoringMathTea, a sophisticated RAT targeting UAV tech firms. Stay vigilant against advanced cyber threats. #CyberSecurity #LazarusGroup #ScoringMathTea Link: thedailytechfeed.com/lazarus-grou...
November 19, 2025 at 6:05 PM
Grupo cibercriminoso atinge indústria europeia de drones.
Os investigadores da ESET detetaram uma nova Operação DreamJob do grupo Lazarus, ligado à Coreia do Norte,
O malware ScoringMathTea foi detetado em Portugal, Alemanha, Índia, Polónia, Reino Unido e Itália
🤨🤨
pplware.sapo.pt/internet/gru...
Grupo cibercriminoso atinge indústria europeia de drones
Os investigadores da ESET detetaram uma nova campanha da Operação DreamJob, conduzida pelo grupo Lazarus.
pplware.sapo.pt
November 1, 2025 at 4:31 AM
ESET researchers have identified a new wave of Operation DreamJob, linked to North Korea's Lazarus Group, targeting European defense contractors involved in drone development. The attackers used fake job ads to deploy the remote-access trojan ScoringMathTea, aiming to steal proprietary data.
How Lazarus Group used fake job ads to spy on Europe’s drone and defense sector
www.helpnetsecurity.com
October 23, 2025 at 7:33 PM
Researchers said they observed North Korean hackers stealing proprietary information and manufacturing know-how regarding unmanned aerial vehicles therecord.media/north-korea-...
North Korean hacking group targeting European drone maker with ScoringMathTea malware
Researchers at ESET said they found evidence of a new tentacle of the long-running Operation DreamJob campaign — where North Korea’s Lazarus group sends malware-laden emails purporting to be from recr...
therecord.media
October 24, 2025 at 1:08 AM
北朝鮮のハッキンググループLazarus Groupが、ドローン等の軍事装備を製造する、欧州の少なくとも3社を攻撃した。長期にわたるOperation DreamJobキャンペーンの新たな動きで、大手企業の採用担当者を装ったメールを送る。 therecord.media/north-korea-...
North Korean hacking group targeting European drone maker with ScoringMathTea malware
Researchers at ESET said they found evidence of a new tentacle of the long-running Operation DreamJob campaign — where North Korea’s Lazarus group sends malware-laden emails purporting to be from recr...
therecord.media
October 24, 2025 at 7:32 AM
North Korea’s Lazarus Group shifts focus to European UAV firms in Operation DreamJob.
💻 Malware: ScoringMathTea RAT
🎯 Objective: steal drone design data & tech secrets

#CyberSecurity #LazarusGroup #APT #DroneSecurity #DefenseIndustry
October 24, 2025 at 6:06 PM
North Korean hacking group targeting European drone maker with ScoringMathTea malware
North Korean hacking group targeting European drone maker with ScoringMathTea malware
Researchers at ESET said they found evidence of a new tentacle of the long-running Operation DreamJob campaign — where North Korea’s Lazarus group sends malware-laden emails purporting to be from recruiters at top companies.
therecord.media
October 24, 2025 at 1:27 AM
Nation-State Actor’s Arsenal: An In-Depth Look at Lazarus’ ScoringMathTea
Nation-State Actor’s Arsenal: An In-Depth Look at Lazarus’ ScoringMathTea
0x0d4y.blog
November 18, 2025 at 7:54 PM
ScoringMathTea: Inside Lazarus Group’s New Stealth C++ RAT Targeting Ukraine’s UAV Defense

Introduction A new chapter in the modern cyber battlefield has opened, and it begins with a shadow slipping through the networks that power Ukraine’s unmanned aerial defense. That shadow has a…
ScoringMathTea: Inside Lazarus Group’s New Stealth C++ RAT Targeting Ukraine’s UAV Defense
Introduction A new chapter in the modern cyber battlefield has opened, and it begins with a shadow slipping through the networks that power Ukraine’s unmanned aerial defense. That shadow has a name—ScoringMathTea, a modular C++ remote-access trojan operated by the notorious Lazarus Group. Its mission: to infiltrate, persist, and quietly extract intelligence from UAV defense contractors. The attack chain is coldly precise, engineered with layers of deception—polyalphabetic decryption, reflective injection, hashed API calls, and encrypted command-and-control pathways.
undercodenews.com
November 28, 2025 at 7:37 AM
Nation-State Actor's Arsenal: An In-Depth Look At Lazarus' ScoringMathTea https://packetstorm.news/news/view/39531 #news
November 18, 2025 at 5:41 PM
Deobfuscating Lazarus: How a Custom Alphabet Unlocks Advanced Threat Detection

Introduction: The Lazarus APT group, a sophisticated state-sponsored actor, continues to evolve its tradecraft, employing advanced obfuscation techniques to hide in plain sight. A recent analysis of their…
Deobfuscating Lazarus: How a Custom Alphabet Unlocks Advanced Threat Detection
Introduction: The Lazarus APT group, a sophisticated state-sponsored actor, continues to evolve its tradecraft, employing advanced obfuscation techniques to hide in plain sight. A recent analysis of their "ScoringMathTea" RAT uncovered a novel string obfuscation method using a custom alphabet, presenting a significant hurdle for static analysis. This article delves into the technical specifics of this technique and provides actionable tools and methodologies for defenders to deobfuscate such threats, turning an evasion tactic into a powerful detection opportunity.
undercodetesting.com
November 4, 2025 at 4:52 AM
Feed: "GBHackers Security | #1 Globally Trusted Cyber Security News Platform"
By: Mayura Kathir on Tuesday, November 18, 2025
Lazarus APT Group’s New ScoringMathTea RAT Enhances Remote Command Execution and More
The Lazarus APT Group, an advanced persistent threat (APT) attributed to North Korea, has deployed a sophisticated new Remote Access Trojan (RAT) called ScoringMathTea.
gbhackers.com
November 18, 2025 at 8:23 PM
Feed: "The Hacker News"
By: info@thehackernews.com (The Hacker News) on Thursday, October 23, 2025
North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets
North Korean Lazarus Group targets European defense firms with ScoringMathTea malware in new espionage wave.
thehackernews.com
October 23, 2025 at 10:18 PM
North Korean hacking group targeting European drone maker with ScoringMathTea malware https://therecord.media/north-korea-hackers-target-europe-drone-makers
October 24, 2025 at 1:47 AM
北朝鮮ハッカー集団が偽求人でUAV企業を攻撃 – 欧州防衛産業を標的にドローン技術窃取
innovatopia.jp/cyber-securi...

今回の攻撃が示すのは、サイバー攻撃の標的が「組織」から「技術そのもの」へとシフトしている現実です。北朝鮮のLazarus Groupは、少なくとも2009年から活動する世界で最も早くから活動が確認されているAPT(Advanced Persistent Threat)グループの一つで、長年にわたり防衛産業や航空宇宙分野を標的としてきました。今回の作戦では、破壊ではなく「知的財産の窃取」という明確な目的を持っています。
北朝鮮ハッカー集団が偽求人でUAV企業を攻撃 – 欧州防衛産業を標的にドローン技術窃取
北朝鮮のハッカー集団Lazarus Groupが、魅力的な偽求人でヨーロッパの防衛産業エンジニアを標的とした新たなサイバー攻撃を展開。ESETの研究者が2025年3月から観測した攻撃では、UAV技術の窃取が目的とされ、トロイの木馬化されたPDFリーダーとScoringMathTeaマルウェアが使用されている。
innovatopia.jp
October 27, 2025 at 1:31 AM
北朝鮮のハッキンググループがScoringMathTeaマルウェアで欧州のドローンメーカーを標的に

北朝鮮で最も活発なハッキンググループの一つが、ドローンやその他の軍事装備品を製造している少なくとも3つの欧州企業を標的にしている。

ESETの研究者らは、長期にわたって続いている「オペレーション・ドリームジョブ」攻撃の新たな手掛かりの証拠を発見したと発表した。この攻撃では、北朝鮮のラザルス集団が大手企業のリクルーターを装ってマルウェアを仕込んだメールを送信している。

このキャンペーンを発見したESETの研究員ピーター・カルナイ氏は、最近の攻撃は無人航空機に関する機密情報や製造ノウ...
North Korean hacking group targeting European drone maker with ScoringMathTea malware
Researchers at ESET said they found evidence of a new tentacle of the long-running Operation DreamJob campaign — where North Korea’s Lazarus group sends malware-laden emails purporting to be from recr...
therecord.media
October 25, 2025 at 8:22 AM
北朝鮮のハッカー、偽の求人情報で防衛技術者を誘い込みドローンの秘密を盗む

北朝鮮とつながりのある脅威アクターらが、 「オペレーション・ドリーム・ジョブ」として知られる長期にわたる攻撃活動の一環として、防衛産業で活動する欧州企業を標的とした新たな一連の攻撃に関与していると考えられている。

「これらの企業の中には、無人航空機(UAV)分野に深く関わっているところもあり、今回の作戦は北朝鮮のドローン計画拡大に向けた現在の取り組みと関連している可能性を示唆している」と、ESETのセキュリティ研究者ピーター・カルナイ氏とアレクシ・ラピン氏はハッカーニュースに共有されたレポートの中で述べた。
North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets
North Korean Lazarus Group targets European defense firms with ScoringMathTea malware in new espionage wave.
thehackernews.com
October 25, 2025 at 8:01 AM
"Nation-State Actor’s Arsenal: An In-Depth Look at Lazarus’ ScoringMathTea" published by 0x0d4y. #Lazarus, #ScoringMathTea, #DPRK, #CTI https://0x0d4y.blog/arsenal-analysis-of-a-nation-state-actor-an-in-depth-look-at-lazarus-scoringmathtea/
November 18, 2025 at 11:30 PM
October 23, 2025 at 1:30 PM