DBLL Dropper is a custom Lazarus Group malware tool associated with Operation Dream Job. The provided content identifies it as one of several bespoke tools developed by Lazarus for that campaign, alongside Sumarta, Torisma, and DRATzarus. Operation Dream Job used job-themed social engineering, including fake LinkedIn recruiter personas, fake email accounts, and malicious Office documents such as DOCX and DOTM files with VBA macros, template injection, and remote XSL scripts to deliver malware. The campaign targeted enterprise Windows environments, including Windows IIS servers, and involved command-and-control over HTTP/HTTPS, use of cloud services such as Dropbox and OneDrive, and exfiltration of stolen data including via a custom dbxcli build to Dropbox. The broader campaign behavior included Active Directory account discovery, PowerShell and command shell execution, persistence via Startup-folder LNK files and scheduled tasks, use of regsvr32 and rundll32, and defense evasion through code signing, packing, encryption/encoding, file deletion, and debugger checks. High-confidence attribution in the content links DBLL Dropper to Lazarus Group and specifically to Operation Dream Job; no standalone indicators of compromise specific to DBLL Dropper are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom Lazarus dropper used in Operation Dream Job.
Dropper/loader used by Lazarus Group in Operation Dream Job.
Custom Lazarus-developed dropper used to deliver additional payloads during Operation Dream Job.
Dropper used by Lazarus Group in Operation Dream Job.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.