LiveActive security incident?Get immediate response
MITRE ATT&CK® Campaign

C0022: Operation Dream Job

Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.[1][2][3][4]

EnterpriseC0022CampaignObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

C0022: Operation Dream Job describes [Operation Dream Job](https://attack.mitre.org/campaigns/C0022) was a cyber espionage operation likely conducted by [Lazarus Group](https://attack.mitre.org/groups/G0032) that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and cod...

Executive priority

C0022: Operation Dream Job is an official MITRE ATT&CK campaign. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate C0022: Operation Dream Job by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether C0022: Operation Dream Job appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Operation Dream Job

Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between Operation Dream Job, Operation North Star, and Operation Interception; by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

55 rows
DomainIDNameRelationship / procedure
EnterpriseT1614.001System Language DiscoverySub-technique

During Operation Dream Job, Lazarus Group deployed malware designed not to run on computers set to Korean, Japanese, or Chinese in Windows language preferences.[1]

EnterpriseT1608.001Upload MalwareSub-technique

For Operation Dream Job, Lazarus Group used compromised servers to host malware.[1][3][2][5]

EnterpriseT1218.011Rundll32Sub-technique

During Operation Dream Job, Lazarus Group executed malware with `C:\\windows\system32\rundll32.exe "C:\ProgramData\ThumbNail\thumbnail.db"`, `CtrlPanel S-6-81-3811-75432205-060098-6872 0 0 905`.[1][3][2]

EnterpriseT1106Native API

During Operation Dream Job, Lazarus Group used Windows API `ObtainUserAgentString` to obtain the victim's User-Agent and used the value to connect to their C2 server.[2]

EnterpriseT1585.001Social Media AccountsSub-technique

For Operation Dream Job, Lazarus Group created fake LinkedIn accounts for their targeting efforts.[1][3]

EnterpriseT1036.008Masquerade File TypeSub-technique

During Operation Dream Job, Lazarus Group disguised malicious template files as JPEG files to avoid detection.[2][3]

EnterpriseT1070.004File DeletionSub-technique

During Operation Dream Job, Lazarus Group removed all previously delivered files from a compromised computer.[3]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

During Operation Dream Job, Lazarus Group placed LNK files into the victims' startup folder for persistence.[2]

EnterpriseT1497.001System ChecksSub-technique

During Operation Dream Job, Lazarus Group used tools that conducted a variety of system checks to detect sandboxes or VMware services.[1]

EnterpriseT1059.005Visual BasicSub-technique

During Operation Dream Job, Lazarus Group executed a VBA written malicious macro after victims download malicious DOTM files; Lazarus Group also used Visual Basic macro code to extract a double Base64 encoded DLL implant.[1][2]

EnterpriseT1608.002Upload ToolSub-technique

For Operation Dream Job, Lazarus Group used multiple servers to host malicious tools.[3]

EnterpriseT1105Ingress Tool Transfer

During Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host.[1][3][2]

EnterpriseT1585.002Email AccountsSub-technique

During Operation Dream Job, Lazarus Group created fake email accounts to correspond with fake LinkedIn personas; Lazarus Group also established email accounts to match those of the victim as part of their BEC attempt.[3]

EnterpriseT1584.001DomainsSub-technique

For Operation Dream Job, Lazarus Group compromised domains in Italy and other countries for their C2 infrastructure.[2][5]

EnterpriseT1583.004ServerSub-technique

During Operation Dream Job, Lazarus Group acquired servers to host their malicious tools.[3]

EnterpriseT1573.001Symmetric CryptographySub-technique

During Operation Dream Job, Lazarus Group used an AES key to communicate with their C2 server.[2]

EnterpriseT1204.001Malicious LinkSub-technique

During Operation Dream Job, Lazarus Group lured users into executing a malicious link to disclose private account information or provide initial access.[1][3]

EnterpriseT1059.001PowerShellSub-technique

During Operation Dream Job, Lazarus Group used PowerShell commands to explore the environment of compromised victims.[3]

EnterpriseT1591Gather Victim Org Information

For Operation Dream Job, Lazarus Group gathered victim organization information to identify specific targets.[1]

EnterpriseT1583.001DomainsSub-technique

During Operation Dream Job, Lazarus Group registered a domain name identical to that of a compromised company as part of their BEC effort.[3]

EnterpriseT1221Template Injection

During Operation Dream Job, Lazarus Group used DOCX files to retrieve a malicious document template/DOTM file.[1][2]

EnterpriseT1497.003Time Based ChecksSub-technique

During Operation Dream Job, Lazarus Group used tools that collected `GetTickCount` and `GetSystemTimeAsFileTime` data to detect sandbox or VMware services.[1]

EnterpriseT1589Gather Victim Identity Information

For Operation Dream Job, Lazarus Group conducted extensive reconnaissance research on potential targets.[1]

EnterpriseT1553.002Code SigningSub-technique

During Operation Dream Job, Lazarus Group digitally signed their own malware to evade detection.[3]

EnterpriseT1005Data from Local System

During Operation Dream Job, Lazarus Group used malicious Trojans and DLL files to exfiltrate data from an infected host.[1][2]

EnterpriseT1110Brute Force

During Operation Dream Job, Lazarus Group performed brute force attacks against administrator accounts.[3]

EnterpriseT1041Exfiltration Over C2 Channel

During Operation Dream Job, Lazarus Group exfiltrated data from a compromised host to actor-controlled C2 servers.[1]

EnterpriseT1534Internal Spearphishing

During Operation Dream Job, Lazarus Group conducted internal spearphishing from within a compromised organization.[1]

EnterpriseT1684.001ImpersonationSub-technique

During Operation Dream Job, Lazarus Group impersonated HR hiring personnel through LinkedIn messages and conducted interviews with victims in order to deceive them into downloading malware.[1][3][4]

EnterpriseT1583.006Web ServicesSub-technique

During Operation Dream Job, Lazarus Group used file hosting services like DropBox and OneDrive.[1]

EnterpriseT1566.003Spearphishing via ServiceSub-technique

During Operation Dream Job, Lazarus Group sent victims spearphishing messages via LinkedIn concerning fictitious jobs.[1][3]

EnterpriseT1591.004Identify RolesSub-technique

During Operation Dream Job, Lazarus Group targeted specific individuals within an organization with tailored job vacancy announcements.[1][3]

EnterpriseT1053.005Scheduled TaskSub-technique

During Operation Dream Job, Lazarus Group created scheduled tasks to set a periodic execution of a remote XSL script.[3]

EnterpriseT1204.002Malicious FileSub-technique

During Operation Dream Job, Lazarus Group lured victims into executing malicious documents that contained "dream job" descriptions from defense, aerospace, and other sectors.[1][2]

EnterpriseT1588.003Code Signing CertificatesSub-technique

During Operation Dream Job, Lazarus Group used code signing certificates issued by Sectigo RSA for some of its malware and tools.[3]

EnterpriseT1087.002Domain AccountSub-technique

During Operation Dream Job, Lazarus Group queried compromised victim's active directory servers to obtain the list of employees including administrator accounts.[3]

EnterpriseT1587.002Code Signing CertificatesSub-technique

During Operation Dream Job, Lazarus Group digitally signed their malware and the dbxcli utility.[3]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

During Operation Dream Job, Lazarus Group sent emails with malicious attachments to gain unauthorized access to targets' computers.[1][2]

EnterpriseT1505.004IIS ComponentsSub-technique

During Operation Dream Job, Lazarus Group targeted Windows servers running Internet Information Systems (IIS) to install C2 components.[2]

EnterpriseT1083File and Directory Discovery

During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters.[1]

EnterpriseT1218.010Regsvr32Sub-technique

During Operation Dream Job, Lazarus Group used `regsvr32` to execute malware.[3]

EnterpriseT1047Windows Management Instrumentation

During Operation Dream Job, Lazarus Group used WMIC to executed a remote XSL script.[3]

EnterpriseT1027.002Software PackingSub-technique

During Operation Dream Job, Lazarus Group packed malicious .db files with Themida to evade detection.[1][2][5]

EnterpriseT1588.002ToolSub-technique

For Operation Dream Job, Lazarus Group obtained tools such as Wake-On-Lan, Responder, ChromePass, and dbxcli.[1][3]

EnterpriseT1071.001Web ProtocolsSub-technique

During Operation Dream Job, Lazarus Group uses HTTP and HTTPS to contact actor-controlled C2 servers.[2]

EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

During Operation Dream Job, Lazarus Group used a custom build of open-source command-line dbxcli to exfiltrate stolen data to Dropbox.[3][1]

EnterpriseT1622Debugger Evasion

During Operation Dream Job, Lazarus Group used tools that used the `IsDebuggerPresent` call to detect debuggers.[1]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64.[1][3][2][5]

EnterpriseT1220XSL Script Processing

During Operation Dream Job, Lazarus Group used a remote XSL script to download a Base64-encoded DLL custom downloader.[3]

EnterpriseT1587.001MalwareSub-technique

For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations.[1][3][2][5]

EnterpriseT1059.003Windows Command ShellSub-technique

During Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell.[3][2]

EnterpriseT1584.004ServerSub-technique

For Operation Dream Job, Lazarus Group compromised servers to host their malicious tools.[1][3][2]

EnterpriseT1593.001Social MediaSub-technique

For Operation Dream Job, Lazarus Group used LinkedIn to identify and target employees within a chosen organization.[3]

EnterpriseT1566.002Spearphishing LinkSub-technique

During Operation Dream Job, Lazarus Group sent malicious OneDrive links with fictitious job offer advertisements via email.[1][3]

EnterpriseT1560.001Archive via UtilitySub-technique

During Operation Dream Job, Lazarus Group archived victim's data into a RAR file.[3]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0032: Lazarus Group

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). [1] [2] Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.[3]

North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.[4][5][6]

MalwareEnterprise

S0678: Torisma

Torisma is a second stage implant designed for specialized monitoring that has been used by Lazarus Group. Torisma was discovered during an investigation into the 2020 Operation North Star campaign that targeted the defense sector.[1]

Windows
ToolEnterprise

S0174: Responder

Responder is an open source tool used for LLMNR, NBT-NS and MDNS poisoning, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication. [1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.2
Created
Modified
Raw hash
0954790b071d74e4...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.2Current bundle0954790b071d…
19.11.2Older bundle61eb67786367…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    ClearSky Lazarus Aug 2020

    ClearSky Research Team. (2020, August 13). Operation 'Dream Job' Widespread North Korean Espionage Campaign. Retrieved December 20, 2021.

    Open source URL
  2. [2]
    McAfee Lazarus Jul 2020

    Cashman, M. (2020, July 29). Operation North Star Campaign. Retrieved December 20, 2021.

    Open source URL
  3. [3]
    ESET Lazarus Jun 2020

    Breitenbacher, D and Osis, K. (2020, June 17). OPERATION IN(TER)CEPTION: Targeted Attacks Against European Aerospace and Military Companies. Retrieved December 20, 2021.

    Open source URL
  4. [4]
    The Hacker News Lazarus Aug 2022

    Lakshmanan, R. (2022, August 17). North Korea Hackers Spotted Targeting Job Seekers with macOS Malware. Retrieved April 10, 2023.

    Open source URL
  5. [5]
    McAfee Lazarus Nov 2020

    Beek, C. (2020, November 5). Operation North Star: Behind The Scenes. Retrieved December 20, 2021.

    Open source URL
  6. [6]
    Operation Interception

    (Citation: ESET Lazarus Jun 2020)

  7. [7]
    Operation North Star

    (Citation: McAfee Lazarus Jul 2020)(Citation: McAfee Lazarus Nov 2020)

  8. [8]
    mitre-attackC0022
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.