Campaign, Sep 2019 to Aug 2020.View on attack.mitre.org
Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host. |
| T1027.002 Software Packing |
During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection. |
| T1027.013 Encrypted/Encoded File |
During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64. |
| T1036.008 Masquerade File Type |
During Operation Dream Job, Lazarus Group disguised malicious template files as JPEG files to avoid detection. |
| T1041 Exfiltration Over C2 Channel |
During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers. |
| T1047 Windows Management Instrumentation |
During Operation Dream Job, Lazarus Group used WMIC to executed a remote XSL script. |
| T1053.005 Scheduled Task |
During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script. |
| T1059.001 PowerShell |
During Operation Dream Job, Lazarus Group used PowerShell commands to explore the environment of compromised victims. |
| T1059.003 Windows Command Shell |
During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell. |
| T1059.005 Visual Basic |
During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant. |
| T1070.004 File Deletion |
During Operation Dream Job, Lazarus Group removed all previously delivered files from a compromised computer. |
| T1071.001 Web Protocols |
During Operation Dream Job, Lazarus Group uses HTTP and HTTPS to contact actor-controlled C2 servers. |
| T1083 File and Directory Discovery |
During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters. |
| T1087.002 Domain Account |
During Operation Dream Job, Lazarus Group queried compromised victim's active directory servers to obtain the list of employees including administrator accounts. |
| T1105 Ingress Tool Transfer |
During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.