From Dream Job to Malware: DreamLoaders in Lazarus’ Recent Campaign
2025-10-24 • Lab52 •
Lab52 analyzed August 2025 Lazarus DreamJob artifacts and found a modular loader set it calls DreamLoaders, including a trojanized TightVNC client, Webservices.dll, radcui.dll, HideFirstLetter.dll, and TSVIPSrv.dll. The campaign aimed to get administrators in targeted organizations to run decoy software, then used DLL sideloading with legitimate Windows binaries, encrypted Base64 payloads, RC4-decrypted paths, and malicious service execution to stage additional components. HideFirstLetter.dll attempted Microsoft OAuth authentication and Microsoft Graph access to retrieve a compromised SharePoint URL, while TSVIPSrv.dll loaded encrypted .mui payload files and showed 85% code similarity to the payload recovered from the trojanized TightVNC sample. The reuse of identical .mui payloads across different compromised machines suggests coordinated deployment and gives defenders concrete hashes, SharePoint domains, loader names, and sideloading behaviors to hunt in DreamJob-related intrusions.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | aefc12b500b58fbc09ebbf34fe64b34… | 2025-10-24 | 2025-11-20 |
| HASH | 0fdd97a597380498f6b2d491f8f50da… | 2025-10-24 | 2025-11-20 |
| HASH | b3d7a3c3dedaa873e81b1676b6c0027… | 2025-10-24 | 2025-10-24 |
| HASH | 26bd4aab63563e77ca426c23b11d18d… | 2025-10-24 | 2025-10-24 |
| HASH | 855baa2ff0c3e958a660ae84a048ce0… | 2025-10-24 | 2025-10-24 |
| HASH | fa014db2936da21af5943cc8f3656ad… | 2025-10-24 | 2025-10-24 |
| HASH | 473726dd9bc034564c4c7b951df12d1… | 2025-10-24 | 2025-10-24 |