Sumarta is a custom malware/tool developed and used by the Lazarus Group, specifically referenced as part of Operation Dream Job. In the provided content, it is consistently listed alongside other Lazarus tools including DBLL Dropper, Torisma, and DRATzarus. Operation Dream Job is described as a Lazarus campaign centered on job-themed social engineering, including fake LinkedIn recruiter personas, fake email accounts, spearphishing, malicious DOCX/DOTM documents, VBA macros, template injection, and remote XSL-based execution to deliver malware. The broader campaign targeted enterprise environments and included reconnaissance of victim organizations, compromise of Active Directory servers to obtain employee and administrator account lists, use of lookalike and compromised domains and servers for command-and-control, and use of Dropbox, OneDrive, HTTP, and HTTPS for staging and communications. Post-compromise activity associated with the campaign included PowerShell and command shell execution, persistence via Startup-folder LNK files and scheduled tasks, data collection and document searches for security and financial information, RAR archiving, exfiltration over C2 and to Dropbox using a custom dbxcli build, and defense evasion through code signing, packing, XOR/Base64 encoding, debugger checks, file deletion, and avoiding execution on systems configured for Korean, Japanese, or Chinese language settings. The content does not provide malware-family-specific technical behavior or indicators of compromise unique to Sumarta beyond its attribution to Lazarus Group and its use in Operation Dream Job.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For Operation Dream Job, Lazarus Group developed custom tools such as Sumarta, DBLL Dropper, Torisma, and DRATzarus for their operations.
1 distinct technique documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom Lazarus malware/tool developed for Operation Dream Job.
Custom tool/malware used by Lazarus Group in Operation Dream Job.
Custom Lazarus-developed malware/tooling used during Operation Dream Job.
Custom tool used by Lazarus Group in Operation Dream Job.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.