Overview
Operation Dream Job (MITRE ATT&CK ID C0022) was a cyber espionage operation likely conducted by Lazarus Group, per MITRE’s campaign profile, targeting defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. MITRE documents at least one case where the actors tried to monetize their network access to conduct a business email compromise (BEC) operation — a financially motivated pivot layered on top of an otherwise espionage-focused campaign.
In 2020, per MITRE’s citations, security researchers noted overlapping TTPs — including fake job lures and code similarities — between Operation Dream Job, Operation North Star, and Operation Interception. By 2022, MITRE notes security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.
Timeline
Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from September 2019 to August 2020.
Actors and malware involved (per MITRE ATT&CK relationship data)
MITRE ATT&CK attributes this campaign to Lazarus Group. Malware documented in this campaign includes Torisma, Responder, and DRATzarus.
What we don’t have
MITRE’s own attribution language (“likely conducted by”) reflects an assessment, not absolute certainty. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no data on the BEC operation’s specific financial outcome beyond MITRE’s note that it was attempted.
Frequently Asked Questions
What was Operation Dream Job? A cyber espionage campaign, per MITRE ATT&CK, likely conducted by Lazarus Group using fake job-offer lures against defense, aerospace, and government targets, active September 2019 to August 2020.
Is Operation Dream Job the same as Operation North Star? Per MITRE’s documentation, by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation North Star and Operation Interception, based on overlapping TTPs and code similarities.
Was this purely an espionage campaign? MITRE’s data notes at least one documented case where the actors also attempted a business email compromise operation to monetize their access — a financial motive layered onto the primary espionage objective.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0022, aggregated August 25, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.