{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lazarus-breaches-spanish-aerospace-firm-with-fake-meta-recruiter-coding"},"incident":{"title":"Lazarus breaches Spanish aerospace firm with fake Meta recruiter coding challenge","date":"2022","date_precision":"year","victim_org":"Unnamed aerospace company in Spain","sector":"Defense","country":"Spain","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the recruiter persona was operated manually over LinkedIn Messaging.","outcomes":["Espionage","Data Breach"],"loss_usd":null,"loss_note":"No financial loss reported; the objective was espionage.","records_affected":null,"threat_actor":"Lazarus Group (North Korea), Operation Dream Job","summary":"ESET researchers disclosed in September 2023 that Lazarus operators had compromised an aerospace company in Spain by posing as a Meta recruiter on LinkedIn and sending employees trojanised C++ coding challenges. Execution of the fake tests delivered a previously undocumented backdoor, LightlessCan, alongside loaders and a simplified remote access tool. The intrusion occurred in 2022 and was part of the long-running Operation Dream Job campaign against defence and aerospace targets.","how_it_worked":"A fake recruiter contacted employees through LinkedIn Messaging claiming to be running a Meta hiring process. The candidate was sent two supposed C++ programming tests, Quiz1.exe and Quiz2.exe, packaged inside ISO images hosted on cloud storage; one printed 'Hello, World!' and the other computed Fibonacci numbers, so the tasks appeared genuine. Running them side-loaded a malicious DLL that installed the NickelLoader downloader, which fetched miniBlindingCan and LightlessCan. LightlessCan supports up to 68 commands and reimplements many Windows utilities internally rather than spawning visible processes, reducing the telemetry available to endpoint monitoring during the espionage phase.","lessons":"Recruitment materials should never be executed on corporate endpoints; disposable virtual machines for candidate exercises plus application allow-listing eliminate this entire vector.","confidence":"Confirmed","sources":[{"title":"Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company","url":"https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/","publisher":"ESET WeLiveSecurity"},{"title":"North Korea-linked Lazarus impersonates Meta on LinkedIn to attack an aerospace company in Spain","url":"https://www.eset.com/us/about/newsroom/press-releases/north-korea-linked-lazarus-impersonates-meta-on-linkedin-to-attack-an-aerospace-company-in-spain/","publisher":"ESET"},{"title":"Lazarus hackers breach aerospace firm with new LightlessCan malware","url":"https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-aerospace-firm-with-new-lightlesscan-malware/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-lazarus-breaches-spanish-aerospace-firm-with-fake-meta-recruiter-coding","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-lazarus-breaches-spanish-aerospace-firm-with-fake-meta-recruiter-coding"}}