Campaign · all campaigns
Operation Dream JobC0022 state
🇰🇵 KP · RGB · Bureau 121 / Lab 110
aka Operation Dream Job, Operation North Star, Operation Interception
Run by Lazarus Group
Last updated: 2026-08-21
About this actor
[Operation Dream Job](https://attack.mitre.org/campaigns/C0022) was a cyber espionage operation likely conducted by [Lazarus Group](https://attack.mitre.org/groups/G0032) that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between [Operation Dream Job](https://attack.mitre.org/campaigns/C0022), Operation North Star, and Operation Interception; by 2022 security researchers described [Operation Dream Job](https://attack.mitre.org/campaigns/C0022) as an umbrella term covering both Operation Interception and Operation North Star.(Citation: ClearSky Lazarus Aug 2020)(Citation: McAfee Lazarus Jul 2020)(Citation: ESET Lazarus Jun 2020)(Citation: The Hacker News Lazarus Aug 2022)
Source: MITRE ATT&CK
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 81 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 2 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2026-31635 | 6.0 | 7.5 | 0.0082 | 2026-04-24 | see CVE |
CVE-2026-45585 | 5.5 | 6.8 | 0.0135 | 2026-05-20 | see CVE |
CVE-2018-2025010 | 0.0 | 0.0 | 0.0000 | see CVE |
T1005Data from Local System ↗T1027Obfuscated Files or Information ↗T1027.002Software Packing ↗T1027.013Encrypted/Encoded File ↗T1036Masquerading ↗T1036.008Masquerade File Type ↗T1041Exfiltration Over C2 Channel ↗T1047Windows Management Instrumentation ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1059.005Visual Basic ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1083File and Directory Discovery ↗T1087Account Discovery ↗T1087.002Domain Account ↗T1105Ingress Tool Transfer ↗T1106Native API ↗T1110Brute Force ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1218System Binary Proxy Execution ↗T1218.010Regsvr32 ↗T1218.011Rundll32 ↗T1220XSL Script Processing ↗T1221Template Injection ↗T1497Virtualization/Sandbox Evasion ↗T1497.001System Checks ↗T1497.003Time Based Checks ↗T1505Server Software Component ↗T1505.004IIS Components ↗T1534Internal Spearphishing ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1566.003Spearphishing via Service ↗T1567Exfiltration Over Web Service ↗T1567.002Exfiltration to Cloud Storage ↗T1573Encrypted Channel ↗T1573.001Symmetric Cryptography ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1583.004Server ↗T1583.006Web Services ↗T1584Compromise Infrastructure ↗T1584.001Domains ↗T1584.004Server ↗T1585Establish Accounts ↗T1585.001Social Media Accounts ↗T1585.002Email Accounts ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1587.002Code Signing Certificates ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1588.003Code Signing Certificates ↗T1589Gather Victim Identity Information ↗T1591Gather Victim Org Information ↗T1591.004Identify Roles ↗T1593Search Open Websites/Domains ↗T1593.001Social Media ↗T1608Stage Capabilities ↗T1608.001Upload Malware ↗T1608.002Upload Tool ↗T1614System Location Discovery ↗T1614.001System Language Discovery ↗T1622Debugger Evasion ↗T1684Social Engineering ↗T1684.001Impersonation ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 42 / 81 | 52% |
SI-3 | 33 / 81 | 41% |
CM-2 | 32 / 81 | 40% |
CM-6 | 32 / 81 | 40% |
CM-7 | 25 / 81 | 31% |
CA-7 | 24 / 81 | 30% |
SC-7 | 22 / 81 | 27% |
AC-3 | 19 / 81 | 23% |
AC-6 | 19 / 81 | 23% |
SI-7 | 19 / 81 | 23% |
AC-2 | 18 / 81 | 22% |
AC-4 | 18 / 81 | 22% |
SI-10 | 15 / 81 | 19% |
SI-2 | 14 / 81 | 17% |
RA-5 | 13 / 81 | 16% |
Co-occurring actors
- IndigoZebra 2 shared CVEs
- Threat Group-3390 2 shared CVEs
Similar actors
Similar TTPs
- Mustang Panda 0.36
- Contagious Interview 0.36
- Kimsuky 0.33
- Sandworm Team 0.31
- Magic Hound 0.31
Overlapping CVEs
- IndigoZebra 0.67
- Threat Group-3390 0.33
Active in same years
- SolarWinds Compromise 1.00
- C0027 1.00
- SharePoint ToolShell Exploitation 1.00
- Ke3chang 1.00
- APT12 1.00
Same nation-state
- 3CX Supply Chain Attack 1.00
- Lazarus Group 1.00
- APT37 1.00
- APT38 1.00
- Kimsuky 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Ghost 1.00