ATT&CKCampaignsOperation Dream Job

Operation Dream Job

C0022

Campaign, Sep 2019 to Aug 2020.View on attack.mitre.org

About this campaign

Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.

Techniques used55

Procedure examples55

TechniqueProcedure example
T1005
Data from Local System

During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host.

T1027.002
Software Packing

During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection.

T1027.013
Encrypted/Encoded File

During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64.

T1036.008
Masquerade File Type

During Operation Dream Job, Lazarus Group disguised malicious template files as JPEG files to avoid detection.

T1041
Exfiltration Over C2 Channel

During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers.

T1047
Windows Management Instrumentation

During Operation Dream Job, Lazarus Group used WMIC to executed a remote XSL script.

T1053.005
Scheduled Task

During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script.

T1059.001
PowerShell

During Operation Dream Job, Lazarus Group used PowerShell commands to explore the environment of compromised victims.

T1059.003
Windows Command Shell

During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell.

T1059.005
Visual Basic

During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant.

T1070.004
File Deletion

During Operation Dream Job, Lazarus Group removed all previously delivered files from a compromised computer.

T1071.001
Web Protocols

During Operation Dream Job, Lazarus Group uses HTTP and HTTPS to contact actor-controlled C2 servers.

T1083
File and Directory Discovery

During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters.

T1087.002
Domain Account

During Operation Dream Job, Lazarus Group queried compromised victim's active directory servers to obtain the list of employees including administrator accounts.

T1105
Ingress Tool Transfer

During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host.

View all 55 procedure examples

Attributed groups1

Software3

References4

  1. ClearSky Lazarus Aug 2020 Open source
    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.
  2. ESET Lazarus Jun 2020 Open source
    Breitenbacher, D and Osis, K. (2020, June 17). OPERATION IN(TER)CEPTION: Targeted Attacks Against European Aerospace and Military Companies. Retrieved December 20, 2021.
  3. McAfee Lazarus Jul 2020 Open source
    Cashman, M. (2020, July 29). Operation North Star Campaign. Retrieved December 20, 2021.
  4. The Hacker News Lazarus Aug 2022 Open source
    Lakshmanan, R. (2022, August 17). North Korea Hackers Spotted Targeting Job Seekers with macOS Malware. Retrieved April 10, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.