C0022: Operation Dream Job
Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.CitationClearSky Lazarus Aug 2020CitationMcAfee Lazarus Jul 2020CitationESET Lazarus Jun 2020CitationThe Hacker News Lazarus Aug 2022
Security context for executives and security teams
Operation Dream Job matters because ATT&CK describes it as a cyber espionage campaign using fake job lures against defense, aerospace, government, and other sectors, with at least one reported attempt to monetize access through business email compromise. For leaders, the practical issue is not just malware: it is whether recruiting-themed social engineering, credential exposure, remote execution, persistence, data collection, and exfiltration would be noticed quickly enough to protect sensitive programs and business communications.
Executive priority
Prioritize this as a resilience and sensitive-data protection scenario for organizations with high-value intellectual property, government-facing work, or executives and staff likely to receive career-themed outreach. Leadership should ask whether SOC, identity, email/web security, endpoint, and incident response teams can prove coverage across the full chain: user interaction with a malicious link or file, Windows execution and persistence behaviors, credential attack activity, internal discovery, tool transfer, and exfiltration over web-like command-and-control traffic. It is also useful as audit evidence for security awareness, endpoint monitoring, privileged access controls, and incident response readiness.
Technical view
The campaign object has no ATT&CK-provided detection text and no campaign-level platforms or tactics, so validation should be driven by its relationships. ATT&CK links the campaign to Lazarus Group and to tools including Responder, Torisma, and DRATzarus, plus techniques covering user execution via malicious links/files, PowerShell, Windows command shell, Visual Basic, WMI, Scheduled Task, Regsvr32, Native API, file and directory discovery, domain account discovery, brute force, ingress tool transfer, obfuscation, masqueraded file types, file deletion, web protocol C2, local data collection, and exfiltration over C2. SOC teams should test whether alerts correlate these behaviors into an intrusion narrative rather than treating them as isolated low-severity events.
Likely telemetry
- Email, web gateway, browser, and user-reporting evidence related to fake job lures, malicious links, and malicious files
- Endpoint process creation and command-line telemetry for PowerShell, cmd.exe, WMI, scheduled tasks, regsvr32.exe, Visual Basic-related execution, and unusual native API-driven behavior where available
- Windows event logs and EDR records for task creation, remote/local WMI activity, script execution, file creation/deletion, packed or encoded files, and masqueraded file types
- Identity provider, directory service, VPN, and authentication logs for brute force attempts and domain account enumeration
- Network telemetry for HTTP/S or other web protocol command-and-control patterns, tool transfer, and possible exfiltration over an existing C2 channel
Detection direction
- Because ATT&CK provides no official detection section for this campaign, map detections to the related techniques and confirm they work in the local environment.
- Correlate user-driven execution events from links or files with follow-on interpreter, WMI, scheduled task, regsvr32, tool transfer, discovery, and outbound web traffic rather than relying only on malware signatures.
- Tune for living-off-the-land behavior: PowerShell, cmd, WMI, scheduled tasks, and regsvr32 are legitimate administration tools, so detection should emphasize unusual parent/child processes, command-line content, timing, user context, remote origin, and sequence of actions.
- Validate visibility into credential-access paths, especially brute force signals and Responder-like name-resolution or rogue authentication activity, since these may be missed if identity and network telemetry are not joined.
- Review blind spots around encrypted or packed payloads, masqueraded file types, and file deletion, which can reduce the value of static file signatures and post-incident artifact recovery.
Mitigation priorities
- Start with reducing successful user execution: reinforce verification of unsolicited job or recruiting outreach, and ensure suspicious links/files can be reported and investigated quickly.
- Harden email, web, and endpoint controls for malicious links, malicious files, packed or encoded content, and masqueraded file types; use prevention where feasible but retain telemetry for investigation.
- Strengthen identity controls against brute force and account misuse, including MFA where applicable, lockout/rate-limiting policies, monitoring of domain account enumeration, and review of privileged account exposure.
- Limit and monitor administrative execution paths such as PowerShell, WMI, scheduled tasks, cmd, Visual Basic, and regsvr32 based on business need and role.
- Reduce credential capture opportunities from local name-resolution abuse by reviewing LLMNR/NBT-NS/MDNS exposure and related authentication flows where Responder-like behavior would be material.
Additional notes and limits
The most decision-useful aspect of this campaign object is the combination of social engineering via fake job lures, Windows and cross-platform execution/stealth techniques, credential-focused activity, and data collection/exfiltration relationships. Treat it as a coverage validation scenario for managed detection, incident response, identity security, endpoint detection, and egress monitoring. Sector and country targeting are from the official ATT&CK description; they should inform prioritization but not be treated as proof of current exposure.
ATT&CK does not provide campaign-level platforms, tactics, labels, or official detection guidance for this object. The technical recommendations are inferred only from the supplied ATT&CK relationships and related object descriptions. Local asset inventory, telemetry quality, business process context, and incident evidence are required before assessing exposure or detection coverage.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Operation Dream Job
Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.CitationClearSky Lazarus Aug 2020CitationMcAfee Lazarus Jul 2020CitationESET Lazarus Jun 2020CitationThe Hacker News Lazarus Aug 2022
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
