Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Campaigns/C0022
MITRE ATT&CK Campaign · 2019–2020

Operation Dream Job (C0022)

ShareXLinkedInRedditHN

[Operation Dream Job](https://attack.mitre.org/campaigns/C0022) was a cyber espionage operation likely conducted by [Lazarus Group](https://attack.mitre.org/groups/G0032) that targeted the defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. In at least one case, the cyber actors tried to monetize their network access to conduct a business email compromise (BEC) operation. In 2020, security researchers noted overlapping TTPs, to include fake job lures and code similarities, between [Operation Dream Job](https://attack.mitre.org/campaigns/C0022), Operation North Star, and Operation Interception; by 2022 security researchers described [Operation Dream Job](https://attack.mitre.org/campaigns/C0022) as an umbrella term covering both Operation Interception and Operation North Star.(Citation: ClearSky Lazarus Aug 2020)(Citation: McAfee Lazarus Jul 2020)(Citation: ESET Lazarus Jun 2020)(Citation: The Hacker News Lazarus Aug 2022)

▪Attributed groups (1)

G0032Lazarus Group

▪Techniques used (55)

T1614.001System Language DiscoveryT1608.001Upload MalwareT1218.011Rundll32T1106Native APIT1585.001Social Media AccountsT1036.008Masquerade File TypeT1070.004File DeletionT1547.001Registry Run Keys / Startup FolderT1497.001System ChecksT1059.005Visual BasicT1608.002Upload ToolT1105Ingress Tool TransferT1585.002Email AccountsT1584.001DomainsT1583.004ServerT1573.001Symmetric CryptographyT1204.001Malicious LinkT1059.001PowerShellT1591Gather Victim Org InformationT1583.001DomainsT1221Template InjectionT1497.003Time Based ChecksT1589Gather Victim Identity InformationT1553.002Code SigningT1005Data from Local SystemT1110Brute ForceT1041Exfiltration Over C2 ChannelT1534Internal SpearphishingT1684.001ImpersonationT1583.006Web ServicesT1566.003Spearphishing via ServiceT1591.004Identify RolesT1053.005Scheduled TaskT1204.002Malicious FileT1588.003Code Signing CertificatesT1087.002Domain AccountT1587.002Code Signing CertificatesT1566.001Spearphishing AttachmentT1505.004IIS ComponentsT1083File and Directory DiscoveryT1218.010Regsvr32T1047Windows Management InstrumentationT1027.002Software PackingT1588.002ToolT1071.001Web ProtocolsT1567.002Exfiltration to Cloud StorageT1622Debugger EvasionT1027.013Encrypted/Encoded FileT1220XSL Script ProcessingT1587.001MalwareT1059.003Windows Command ShellT1584.004ServerT1593.001Social MediaT1566.002Spearphishing LinkT1560.001Archive via Utility

▪Software used (3)

S0678TorismamalwareS0174RespondertoolS0694DRATzarusmalware
C0022on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.