← Back to all campaigns
ActiveMITRE ATT&CK

Operation Dream Job

Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.

First observedSep 1, 2019
Last observedAug 1, 2020
Attributed actors1
Source-backed events3
Attribution

Who has been linked to this activity

Each relationship retains its own confidence and source.

Source ReportedActive actor

Lazarus Group

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the Novembe...

mitre-attckReview source
Activity

Campaign timeline

Every date says what it measures so catalog dates are not confused with publication dates.

Cataloged
Attribution

Lazarus Group attributed to this campaign

Attribution confidence: Source Reported.

Last observed
Campaign

Operation Dream Job last observed

The campaign source marks this as the latest known activity date.

MITRE ATT&CKSource
First observed
Campaign

Operation Dream Job first observed

The campaign source marks this as the beginning of the known activity window.

MITRE ATT&CKSource
About the context below

CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.

Investigation context

What the attributed actors are known to use

Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.

ATT&CK techniques 94

Malware and tools 26

  • AppleJeusMalware | Lazarus Group
  • AuditCredMalware | Lazarus Group
  • BADCALLMalware | Lazarus Group
  • BLINDINGCANMalware | Lazarus Group
  • BankshotMalware | Lazarus Group
  • CryptoisticMalware | Lazarus Group
  • DaclsMalware | Lazarus Group
  • DtrackMalware | Lazarus Group
  • ECCENTRICBANDWAGONMalware | Lazarus Group
  • FALLCHILLMalware | Lazarus Group
  • HARDRAINMalware | Lazarus Group
  • HOPLIGHTMalware | Lazarus Group

Indicators 0

No source-linked indicators are available.

Sources

Evidence behind this page

Open the original material before making an attribution or response decision.