TorisMa is a Lazarus Group malware family associated with Operation Dream Job, a highly targeted campaign that used recruiter-themed social engineering to compromise organizations in research, defense, and financial or payments sectors. It is a Windows implant delivered selectively as a second-stage payload only after an earlier-stage infection profiled the victim and backend infrastructure determined the host was of interest, including allow-list based gating by victim network characteristics. This selective deployment model indicates a tailored post-compromise tool used for higher-value targets rather than broad indiscriminate distribution.
The malware supports host reconnaissance and data theft. Reported capabilities include collecting local network configuration details such as IP and MAC address information, obtaining the current system time, and transmitting victim data to actor-controlled command-and-control infrastructure. Its command-and-control traffic is obfuscated through Base64 encoding and additionally protected with XOR and VEST-32 encryption. Samples have also been observed packed with Iz4 compression, consistent with Lazarus tradecraft aimed at hindering analysis and detection. TorisMa uses Windows API functionality during execution.
In the broader Lazarus intrusion chain, TorisMa appears as part of a custom malware ecosystem that includes tools such as Sumarta, DBLL Dropper, and DRATzarus. Delivery in documented Dream Job activity began with spearphishing emails carrying malicious Microsoft Word documents and macros that installed a first-stage reconnaissance implant; only selected victims subsequently received TorisMa. This places TorisMa in a post-exploitation role focused on intelligence collection and exfiltration within carefully curated victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus-associated malware family listed as related malware.
Collects local MAC address via GetAdaptersInfo and the system IP address.
A second-stage Lazarus payload selectively delivered to whitelisted victims after an initial reconnaissance implant. It functions as the final backdoor/payload released only to targets deemed of interest.
Malware that Base64-encodes command-and-control communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.