A Pain in the Mist: Navigating Operation DreamJob’s arsenal

2025-11-20 Orange Cyberdefense

https://www.orangecyberdefense.com/global/blog/cert-news/a-pain-in-the-mist-navigating-operation-dreamjobs-arsenal

Attachments

Navigating_Operation_DreamJob_s_arsenal_1.pdf (2 MB)

Thumbnail for A Pain in the Mist: Navigating Operation DreamJob’s arsenal

Orange Cyberdefense investigated an August 2025 intrusion against an Asian subsidiary of a large European manufacturing organization and assessed that it aligned with Operation DreamJob and UNC2970 with medium confidence. Initial access used a targeted WhatsApp Web job lure sent to a project engineer, leading the victim to open a ZIP containing a malicious PDF, legitimate SumatraPDF executable, and sideloaded libmupdf.dll assessed as a BURNBOOK variant. The actors conducted hands-on-keyboard activity, LDAP discovery, account compromise, pass-the-hash lateral movement, and attempted deployment of TSVIPsrv.dll, assessed as a MISTPEN variant that contacted compromised SharePoint servers for C2. The report lists BURNBOOK, MISTPEN, and wordpad.dll.mui hashes plus SharePoint and compromised WordPress C2 infrastructure, showing Operation DreamJob remains active with frequently modified loaders, backdoors, and social-engineering tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4eeec453e42c2898e2e9870bbee2738… 2025-11-20 2025-11-20
HASH 7b4cb382b364389c3bd1f4736411de1… 2025-11-20 2025-11-20
HASH 083d4a4ef6267c9a0ab57f1e5a2ed45… 2025-11-20 2025-11-20
HASH ec5d14ca011ba8c12f4d51b0d463cf5… 2025-11-20 2025-11-20
HASH e3e0a87e18de05c4abb95fc21f22d6c… 2025-11-20 2025-11-20
URL https://tours-albatros.es/wp-co… 2025-11-20 2025-11-20
URL https://kutahyasmmmo.org/wp-con… 2025-11-20 2025-11-20
DOMAIN isiswauitmedu-my.sharepoint.com 2025-11-20 2025-11-20
DOMAIN kutahyasmmmo.org 2025-11-20 2025-11-20
DOMAIN diakoffice-my.sharepoint.com 2025-11-20 2025-11-20
DOMAIN cseabrahamlincoln-my.sharepoint… 2025-11-20 2025-11-20
DOMAIN aerm-my.sharepoint.com 2025-11-20 2025-11-20
DOMAIN alex2moe-my.sharepoint.com 2025-11-20 2025-11-20
DOMAIN tours-albatros.es 2025-11-20 2025-11-20
HASH aefc12b500b58fbc09ebbf34fe64b34… 2025-10-24 2025-11-20
HASH 0fdd97a597380498f6b2d491f8f50da… 2025-10-24 2025-11-20
URL https://coralsunmarine.com/wp-c… 2025-10-23 2025-11-20
DOMAIN coralsunmarine.com 2025-10-23 2025-11-20
HASH f5873ecd60390e7b86db5ddaf158ed2… 2024-12-23 2025-11-20

Related Actors

Related Reports

« Back