Skip to content
NetarxImpact Database
Fake Job Offer / Recruitment LureNo AI reportedConfirmed

Lazarus breaches Spanish aerospace firm with fake Meta recruiter coding challenge

Unnamed aerospace company in Spain · Defense · Spain · 2022

What happened

ESET researchers disclosed in September 2023 that Lazarus operators had compromised an aerospace company in Spain by posing as a Meta recruiter on LinkedIn and sending employees trojanised C++ coding challenges. Execution of the fake tests delivered a previously undocumented backdoor, LightlessCan, alongside loaders and a simplified remote access tool. The intrusion occurred in 2022 and was part of the long-running Operation Dream Job campaign against defence and aerospace targets.

How the deception worked

A fake recruiter contacted employees through LinkedIn Messaging claiming to be running a Meta hiring process. The candidate was sent two supposed C++ programming tests, Quiz1.exe and Quiz2.exe, packaged inside ISO images hosted on cloud storage; one printed 'Hello, World!' and the other computed Fibonacci numbers, so the tasks appeared genuine. Running them side-loaded a malicious DLL that installed the NickelLoader downloader, which fetched miniBlindingCan and LightlessCan. LightlessCan supports up to 68 commands and reimplements many Windows utilities internally rather than spawning visible processes, reducing the telemetry available to endpoint monitoring during the espionage phase.

AI involvement · No AI reported

No AI element reported; the recruiter persona was operated manually over LinkedIn Messaging.

The control that would have caught it· our reading, not a claim from the sources

Recruitment materials should never be executed on corporate endpoints; disposable virtual machines for candidate exercises plus application allow-listing eliminate this entire vector.

Sources (3)

  1. Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company
    ESET WeLiveSecurity·welivesecurity.comOpen ↗
  2. North Korea-linked Lazarus impersonates Meta on LinkedIn to attack an aerospace company in Spain
    ESET·eset.comOpen ↗
  3. Lazarus hackers breach aerospace firm with new LightlessCan malware
    BleepingComputer·bleepingcomputer.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.