SimplexTea is a Linux backdoor attributed by ESET to the Lazarus group as part of Operation DreamJob. It was publicly described as the final Linux payload in a DreamJob infection chain that used fake job-offer lures, including an HSBC-themed decoy delivered in a ZIP archive. In the observed chain, a 64-bit Go-based Linux downloader named OdicLoader masqueraded as a PDF, opened a decoy document via xdg-open, then retrieved SimplexTea from an OpenDrive cloud storage account and stored it as ~/.config/guiconfigd (SHA-1: 0CA1723AFE261CD85B05C9EF424FC50290DCE7DF). Persistence was established by modifying ~/.bash_profile to execute the payload with output redirected to /dev/null. ESET describes SimplexTea as a Linux backdoor written in C++ and assesses it as an updated rewrite of an earlier Linux backdoor sample, sysnetd (SHA-1: F6760FB1F8B019AF2304EA6410001B63A1809F1D), associated with Lazarus’s BADCALL family. ESET reported that SimplexTea used https://journalide[.]org/djour.php as command-and-control infrastructure; the domain journalide[.]org also figured in reporting around the March 2023 3CX supply-chain compromise, which ESET linked to Lazarus with high confidence. The malware illustrates Lazarus’s cross-platform operations alongside related DreamJob payloads such as LightlessCan for Windows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux payload referenced as part of the Lazarus/Operation DreamJob toolset; specific capabilities are not detailed in the provided content.
Linux backdoor (C++) delivered as the second stage in Lazarus Operation DreamJob. It is downloaded by OdicLoader from OpenDrive, persists via ~/.bash_profile modification, loads encrypted configuration (apdl.cf), and provides C2 over HTTP/HTTPS with AES-GCM + base64, plus capabilities such as file/directory listing, secure deletion, process execution, proxy support, and ZIP exfiltration over the C2 channel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.