From Dream Job to Malware: DreamLoaders in Lazarus’ Recent Campaign

2025-10-24 Lab52

https://lab52.io/blog/dreamloaders/

Thumbnail for From Dream Job to Malware: DreamLoaders in Lazarus’ Recent Campaign

Lab52 analyzed August 2025 Lazarus DreamJob artifacts and found a modular loader set it calls DreamLoaders, including a trojanized TightVNC client, Webservices.dll, radcui.dll, HideFirstLetter.dll, and TSVIPSrv.dll. The campaign aimed to get administrators in targeted organizations to run decoy software, then used DLL sideloading with legitimate Windows binaries, encrypted Base64 payloads, RC4-decrypted paths, and malicious service execution to stage additional components. HideFirstLetter.dll attempted Microsoft OAuth authentication and Microsoft Graph access to retrieve a compromised SharePoint URL, while TSVIPSrv.dll loaded encrypted .mui payload files and showed 85% code similarity to the payload recovered from the trojanized TightVNC sample. The reuse of identical .mui payloads across different compromised machines suggests coordinated deployment and gives defenders concrete hashes, SharePoint domains, loader names, and sideloading behaviors to hunt in DreamJob-related intrusions.

Indicators of Compromise

Type Value First Seen Last Seen
HASH aefc12b500b58fbc09ebbf34fe64b34… 2025-10-24 2025-11-20
HASH 0fdd97a597380498f6b2d491f8f50da… 2025-10-24 2025-11-20
HASH b3d7a3c3dedaa873e81b1676b6c0027… 2025-10-24 2025-10-24
HASH 26bd4aab63563e77ca426c23b11d18d… 2025-10-24 2025-10-24
HASH 855baa2ff0c3e958a660ae84a048ce0… 2025-10-24 2025-10-24
HASH fa014db2936da21af5943cc8f3656ad… 2025-10-24 2025-10-24
HASH 473726dd9bc034564c4c7b951df12d1… 2025-10-24 2025-10-24

Related Actors

Related Reports

« Back