BinMergeLoader is a loader/downloader observed by ESET in a 2025 wave of Lazarus Group Operation DreamJob activity targeting European defense-sector organizations, including companies involved in UAV-related technology. It was built from trojanized WinMerge plugins (including DisplayBinaryFiles and HideFirstLetter) and is described as similar to Mandiant’s MISTPEN. ESET reported that BinMergeLoader leverages the Microsoft Graph API and abuses Microsoft API/Graph tokens for authentication. In the broader intrusion chain, Lazarus used fake job-offer social engineering and trojanized software to gain execution, then employed loaders/downloaders that decrypted later stages with AES-128 or ChaCha20 and loaded them in memory via MemoryModule, keeping the main payload unencrypted off disk. The campaign’s primary payload was ScoringMathTea, a RAT used for full remote control and cyberespionage. BinMergeLoader was associated with Operation DreamJob submissions seen from Spain in August 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"BinMergeLoader mirrors Mandiant’s MISTPEN and abuses Microsoft Graph tokens."
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader used in Operation DreamJob; noted for similarities to Mandiant-tracked MISTPEN and for abusing Microsoft Graph tokens. Used to keep main implants encrypted on disk and load/decrypt payloads in-memory.
Complex downloader/loader used in Operation DreamJob execution chains. Leverages the Microsoft Graph API and uses Microsoft API tokens for authentication; can also reflectively load DLLs and support follow-on payload delivery (e.g., ScoringMathTea).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.