A Pain in the Mist: Navigating Operation DreamJob’s arsenal
2025-11-20 • Orange Cyberdefense •
Attachments
Orange Cyberdefense investigated an August 2025 intrusion against an Asian subsidiary of a large European manufacturing organization and assessed that it aligned with Operation DreamJob and UNC2970 with medium confidence. Initial access used a targeted WhatsApp Web job lure sent to a project engineer, leading the victim to open a ZIP containing a malicious PDF, legitimate SumatraPDF executable, and sideloaded libmupdf.dll assessed as a BURNBOOK variant. The actors conducted hands-on-keyboard activity, LDAP discovery, account compromise, pass-the-hash lateral movement, and attempted deployment of TSVIPsrv.dll, assessed as a MISTPEN variant that contacted compromised SharePoint servers for C2. The report lists BURNBOOK, MISTPEN, and wordpad.dll.mui hashes plus SharePoint and compromised WordPress C2 infrastructure, showing Operation DreamJob remains active with frequently modified loaders, backdoors, and social-engineering tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 4eeec453e42c2898e2e9870bbee2738… | 2025-11-20 | 2025-11-20 |
| HASH | 7b4cb382b364389c3bd1f4736411de1… | 2025-11-20 | 2025-11-20 |
| HASH | 083d4a4ef6267c9a0ab57f1e5a2ed45… | 2025-11-20 | 2025-11-20 |
| HASH | ec5d14ca011ba8c12f4d51b0d463cf5… | 2025-11-20 | 2025-11-20 |
| HASH | e3e0a87e18de05c4abb95fc21f22d6c… | 2025-11-20 | 2025-11-20 |
| URL | https://tours-albatros.es/wp-co… | 2025-11-20 | 2025-11-20 |
| URL | https://kutahyasmmmo.org/wp-con… | 2025-11-20 | 2025-11-20 |
| DOMAIN | isiswauitmedu-my.sharepoint.com | 2025-11-20 | 2025-11-20 |
| DOMAIN | kutahyasmmmo.org | 2025-11-20 | 2025-11-20 |
| DOMAIN | diakoffice-my.sharepoint.com | 2025-11-20 | 2025-11-20 |
| DOMAIN | cseabrahamlincoln-my.sharepoint… | 2025-11-20 | 2025-11-20 |
| DOMAIN | aerm-my.sharepoint.com | 2025-11-20 | 2025-11-20 |
| DOMAIN | alex2moe-my.sharepoint.com | 2025-11-20 | 2025-11-20 |
| DOMAIN | tours-albatros.es | 2025-11-20 | 2025-11-20 |
| HASH | aefc12b500b58fbc09ebbf34fe64b34… | 2025-10-24 | 2025-11-20 |
| HASH | 0fdd97a597380498f6b2d491f8f50da… | 2025-10-24 | 2025-11-20 |
| URL | https://coralsunmarine.com/wp-c… | 2025-10-23 | 2025-11-20 |
| DOMAIN | coralsunmarine.com | 2025-10-23 | 2025-11-20 |
| HASH | f5873ecd60390e7b86db5ddaf158ed2… | 2024-12-23 | 2025-11-20 |