logo

From Dream Job to Malware: DreamLoaders in Lazarus’ Recent Campaign

ID: 4af031ce-c36f-5af3-87da-d07306301648

STIX ID: report--4af031ce-c36f-5af3-87da-d07306301648

Feed Name: Lab52 Blog

Threat Score
90/100

Date Published: 2025-10-24

Date Updated: 2026-04-28

Author: 10ba

...
...

This report describes Lazarus Group's DreamJob campaign leveraging modular 'DreamLoaders'—trojanized TightVNC and multiple DLL loaders loaded via DLL sideloading and a malicious service—to deploy encrypted payloads, perform credential harvesting and access Microsoft/SharePoint resources; the analysis includes artifact behavior, chaining across .mui files, and IOCs (file hashes and domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.