ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host. |
| T1005 Data from Local System |
MalwareDRATzarus | DRATzarus can collect information from a compromised host. |
| T1018 Remote System Discovery |
MalwareDRATzarus | DRATzarus can search for other machines connected to compromised host and attempt to map the network. |
| T1027 Obfuscated Files or Information |
MalwareDRATzarus | DRATzarus can be partly encrypted with XOR. |
| T1027.002 Software Packing |
MalwareDRATzarus | DRATzarus's dropper can be packed with UPX. |
| T1027.002 Software Packing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection. |
| T1027.013 Encrypted/Encoded File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64. |
| T1033 System Owner/User Discovery |
MalwareDRATzarus | DRATzarus can obtain a list of users from an infected machine. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareDRATzarus | DRATzarus has been named `Flash.exe`, and its dropper has been named `IExplorer`. |
| T1041 Exfiltration Over C2 Channel |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers. |
| T1057 Process Discovery |
MalwareDRATzarus | DRATzarus can enumerate and examine running processes to determine if a debugger is present. |
| T1059.005 Visual Basic |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant. |
| T1071.001 Web Protocols |
MalwareDRATzarus | DRATzarus can use HTTP or HTTPS for C2 communications. |
| T1083 File and Directory Discovery |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters. |
| T1105 Ingress Tool Transfer |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareDRATzarus | DRATzarus can deploy additional tools onto an infected machine. |
| T1106 Native API |
MalwareDRATzarus | DRATzarus can use various API calls to see if it is running in a sandbox. |
| T1124 System Time Discovery |
MalwareDRATzarus | DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to inspect system time. |
| T1204.001 Malicious Link |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group lured users into executing a malicious link to disclose private account information or provide initial access. |
| T1204.002 Malicious File |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors. |
| T1218.011 Rundll32 |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`. |
| T1221 Template Injection |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used DOCX files to retrieve a malicious document template/DOTM file. |
| T1497.001 System Checks |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used tools that conducted a variety of system checks to detect sandboxes or VMware services. |
| T1497.003 Time Based Checks |
MalwareDRATzarus | DRATzarus can use the `GetTickCount` and `GetSystemTimeAsFileTime` API calls to measure function timing. DRATzarus can also remotely shut down into sleep mode under specific conditions to evade |
| T1497.003 Time Based Checks |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used tools that collected `GetTickCount` and `GetSystemTimeAsFileTime` data to detect sandbox or VMware services. |
| T1534 Internal Spearphishing |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group conducted internal spearphishing from within a compromised organization. |
| T1566.001 Spearphishing Attachment |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers. |
| T1566.002 Spearphishing Link |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent malicious OneDrive links with fictitious job offer advertisements via email. |
| T1566.003 Spearphishing via Service |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group sent victims spearphishing messages via LinkedIn concerning fictitious jobs. |
| T1567.002 Exfiltration to Cloud Storage |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used a custom build of open-source command-line dbxcli to exfiltrate stolen data to Dropbox. |
| T1583.006 Web Services |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used file hosting services like DropBox and OneDrive. |
| T1584.004 Server |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools. |
| T1585.001 Social Media Accounts |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group created fake LinkedIn accounts for their targeting efforts. |
| T1587.001 Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations. |
| T1588.002 Tool |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group obtained tools such as Wake-On-Lan, Responder, ChromePass, and dbxcli. |
| T1589 Gather Victim Identity Information |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group conducted extensive reconnaissance research on potential targets. |
| T1591 Gather Victim Org Information |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group gathered victim organization information to identify specific targets. |
| T1591.004 Identify Roles |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group targeted specific individuals within an organization with tailored job vacancy announcements. |
| T1608.001 Upload Malware |
CampaignOperation Dream Job | For Operation Dream Job, Lazarus Group used compromised servers to host malware. |
| T1614.001 System Language Discovery |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group deployed malware designed not to run on computers set to Korean, Japanese, or Chinese in Windows language preferences. |
| T1622 Debugger Evasion |
MalwareDRATzarus | DRATzarus can use `IsDebuggerPresent` to detect whether a debugger is present on a victim. |
| T1622 Debugger Evasion |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used tools that used the `IsDebuggerPresent` call to detect debuggers. |
| T1684.001 Impersonation |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group impersonated HR hiring personnel through LinkedIn messages and conducted interviews with victims in order to deceive them into downloading malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.