lab52 · Crawled Jul 25, 2026

From Dream Job to Malware: DreamLoaders in Lazarus’ Recent Campaign

10 IoCs
Read original article ↗

AI Summary

In August 2025, the Lazarus group conducted a targeted campaign using trojanized tools and DLL sideloading techniques as part of their DreamJob operations. The attackers deployed multiple variants of modular loaders, collectively termed 'DreamLoaders', including TSVIPSrv.dll and HideFirstLetter.dll, to execute malicious payloads and extract credentials. These loaders leveraged legitimate system binaries and encrypted resources to evade detection, while communicating with attacker-controlled SharePoint domains. The campaign demonstrates a high degree of code reuse and operational sophistication aimed at compromising organizational administrators.

AI-extracted · verify before operational use

Indicators of Compromise 10 extracted

Type Value Detail
SHA-256 aefc12b500b58fbc09ebbf34fe64b34cb32a27513478f4769447280ad23af4d2 Details →
SHA-256 0fdd97a597380498f6b2d491f8f50da8f903def4ea6e624b89757456c287f92d Details →
SHA-256 fa014db2936da21af5943cc8f3656adb9800173ad86af196f71c6052295fff97 Details →
SHA-256 26bd4aab63563e77ca426c23b11d18d894eef9a727e111be79336e099b22bdd1 Details →
SHA-256 473726dd9bc034564c4c7b951df12d102ff24f7b17b8356f55d36ed6d908882d Details →
SHA-256 b3d7a3c3dedaa873e81b1676b6c0027ae1fd164587299bf65c02bd067ae1a972 Details →
SHA-256 855baa2ff0c3e958a660ae84a048ce006e07cf51ce5192c0de364ee62873980c Details →
Domain alex2moe-my[.]sharepoint[.]com Details →
Domain coralsunmarine[.]com Details →
Domain cseabrahamlincoln-my[.]sharepoint[.]com Details →