dbxcli is a custom-built, modified version of the open-source Dropbox command-line client used by threat actors for data exfiltration to Dropbox. In the provided reporting, it is associated with Lazarus Group activity, including Operation Dream Job, and was also observed in Operation In(ter)ception, where investigators noted possible but unconfirmed Lazarus links. In these campaigns, attackers used job-themed social engineering and LinkedIn personas impersonating HR or hiring staff at aerospace and defense companies to gain initial access, delivering password-protected RAR archives, LNK files, OneDrive-hosted payloads, and other multistage malware components. After compromise, the actors used living-off-the-land binaries such as WMIC, rundll32, regsvr32, certutil, and PowerShell-related tooling, alongside custom malware including downloaders and modular backdoors, before using the custom dbxcli build to exfiltrate stolen victim data to Dropbox. The campaigns targeted aerospace and military companies in Europe and the Middle East, and also involved collection of security and financial information and, in at least one case, attempted business email compromise. The content states that some malware components, including dbxcli, were digitally signed; in Operation In(ter)ception, the downloader, backdoor, and dbxcli were signed with a certificate issued in October 2019 to “16:20 Software, LLC.” No specific dbxcli-specific indicators of compromise beyond its use as a custom Dropbox exfiltration utility are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom-built command-line Dropbox client used to exfiltrate data to Dropbox during Operation Dream Job.
A (custom-built) Dropbox command-line client leveraged to upload/exfiltrate collected victim data to attacker-controlled cloud storage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.