lab52 · Crawled Jul 25, 2026
From Dream Job to Malware: DreamLoaders in Lazarus’ Recent Campaign
10 IoCs
Read original article ↗
AI Summary
In August 2025, the Lazarus group conducted a targeted campaign using trojanized tools and DLL sideloading techniques as part of their DreamJob operations. The attackers deployed multiple variants of modular loaders, collectively termed 'DreamLoaders', including TSVIPSrv.dll and HideFirstLetter.dll, to execute malicious payloads and extract credentials. These loaders leveraged legitimate system binaries and encrypted resources to evade detection, while communicating with attacker-controlled SharePoint domains. The campaign demonstrates a high degree of code reuse and operational sophistication aimed at compromising organizational administrators.
AI-extracted · verify before operational use
Indicators of Compromise 10 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | aefc12b500b58fbc09ebbf34fe64b34cb32a27513478f4769447280ad23af4d2 | Details → |
| SHA-256 | 0fdd97a597380498f6b2d491f8f50da8f903def4ea6e624b89757456c287f92d | Details → |
| SHA-256 | fa014db2936da21af5943cc8f3656adb9800173ad86af196f71c6052295fff97 | Details → |
| SHA-256 | 26bd4aab63563e77ca426c23b11d18d894eef9a727e111be79336e099b22bdd1 | Details → |
| SHA-256 | 473726dd9bc034564c4c7b951df12d102ff24f7b17b8356f55d36ed6d908882d | Details → |
| SHA-256 | b3d7a3c3dedaa873e81b1676b6c0027ae1fd164587299bf65c02bd067ae1a972 | Details → |
| SHA-256 | 855baa2ff0c3e958a660ae84a048ce006e07cf51ce5192c0de364ee62873980c | Details → |
| Domain | alex2moe-my[.]sharepoint[.]com | Details → |
| Domain | coralsunmarine[.]com | Details → |
| Domain | cseabrahamlincoln-my[.]sharepoint[.]com | Details → |