Operation Dream Job is a North Korean intrusion campaign associated with Lazarus Group that uses recruiter and job-offer themed social engineering to gain initial access. The operation is known for approaching targets through professional networking platforms, particularly LinkedIn, with fictitious employment opportunities and then inducing them to open or download malicious content. It has been discussed alongside broader Lazarus activity and overlaps in tradecraft with other North Korean employment-themed operations, but remains a distinct campaign name widely used by defenders. The campaign combines social engineering with post-compromise espionage tradecraft. Reported behaviors include use of compromised servers to host malware, execution of payloads through regsvr32, persistence via LNK shortcuts placed in Startup folders, and exfiltration of stolen data to cloud storage using a customized build of dbxcli. On compromised networks, operators conducted Active Directory account discovery to enumerate employees and administrator accounts, and searched documents for security- and finance-related terms, indicating targeted collection priorities. Malware used in the operation has also been configured to avoid execution on systems with Korean, Japanese, or Chinese language settings, reflecting deliberate victim filtering. Operation Dream Job is best understood as a Lazarus-linked, North Korean espionage campaign centered on fake recruiting lures, selective victiming, enterprise discovery, persistence, and data theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A North Korean social engineering campaign that impersonates recruiters and companies with fake job offers to trick targets into downloading malicious tools during supposed interviews.
Named activity cluster in which malware was configured to avoid execution on systems using Korean, Japanese, or Chinese language settings.
Activity cluster in which Lazarus Group used regsvr32 to execute malware.
Campaign in which Lazarus Group used a custom dbxcli build to exfiltrate stolen data to Dropbox.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.