Cashman, M. (2020, July 29). Operation North Star Campaign. Retrieved December 20, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host. |
| T1027.002 Software Packing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64. |
| T1036.008 Masquerade File Type |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group disguised malicious template files as JPEG files to avoid detection. |
| T1059.003 Windows Command Shell |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell. |
| T1059.005 Visual Basic |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant. |
| T1071.001 Web Protocols |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group uses HTTP and HTTPS to contact actor-controlled C2 servers. |
| T1105 Ingress Tool Transfer |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host. |
| T1106 Native API |
GroupLazarus Group | Lazarus Group has used the Windows API |
| T1106 Native API |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used Windows API `ObtainUserAgentString` to obtain the victim's User-Agent and used the value to connect to their C2 server. |
| T1204.002 Malicious File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors. |
| T1218.011 Rundll32 |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`. |
| T1221 Template Injection |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used DOCX files to retrieve a malicious document template/DOTM file. |
| T1505.004 IIS Components |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group targeted Windows servers running Internet Information Systems (IIS) to install C2 components. |
| T1547.001 Registry Run Keys / Startup Folder |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group placed LNK files into the victims' startup folder for persistence. |
| T1566.001 Spearphishing Attachment |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers. |
| T1573.001 Symmetric Cryptography |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used an AES key to communicate with their C2 server. |
| T1584.001 Domains |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group compromised domains in Italy and other countries for their C2 infrastructure. |
| T1584.004 Server |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools. |
| T1587.001 Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations. |
| T1608.001 Upload Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group used compromised servers to host malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.