Skip to main content
QUIETLYTIC
Campaign

Operation Dream Job

Cyber espionage operation likely conducted by Lazarus Group using fake job lures against defense, aerospace, and government sectors in the US, Israel, Australia, Russia, and India, 2019-2020.

Threat Level
HIGH
Status
Resolved
Actors Involved
Lazarus Group
Targets
Defense, aerospace, and government sectors, United States, Israel, Australia, Russia, India
Also Known As
Operation North Star, Operation Interception

Overview

Operation Dream Job (MITRE ATT&CK ID C0022) was a cyber espionage operation likely conducted by Lazarus Group, per MITRE’s campaign profile, targeting defense, aerospace, government, and other sectors in the United States, Israel, Australia, Russia, and India. MITRE documents at least one case where the actors tried to monetize their network access to conduct a business email compromise (BEC) operation — a financially motivated pivot layered on top of an otherwise espionage-focused campaign.

In 2020, per MITRE’s citations, security researchers noted overlapping TTPs — including fake job lures and code similarities — between Operation Dream Job, Operation North Star, and Operation Interception. By 2022, MITRE notes security researchers described Operation Dream Job as an umbrella term covering both Operation Interception and Operation North Star.

Timeline

Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from September 2019 to August 2020.

Actors and malware involved (per MITRE ATT&CK relationship data)

MITRE ATT&CK attributes this campaign to Lazarus Group. Malware documented in this campaign includes Torisma, Responder, and DRATzarus.

What we don’t have

MITRE’s own attribution language (“likely conducted by”) reflects an assessment, not absolute certainty. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no data on the BEC operation’s specific financial outcome beyond MITRE’s note that it was attempted.

Frequently Asked Questions

What was Operation Dream Job? A cyber espionage campaign, per MITRE ATT&CK, likely conducted by Lazarus Group using fake job-offer lures against defense, aerospace, and government targets, active September 2019 to August 2020.

Is Operation Dream Job the same as Operation North Star? Per MITRE’s documentation, by 2022 security researchers described Operation Dream Job as an umbrella term covering both Operation North Star and Operation Interception, based on overlapping TTPs and code similarities.

Was this purely an espionage campaign? MITRE’s data notes at least one documented case where the actors also attempted a business email compromise operation to monetize their access — a financial motive layered onto the primary espionage objective.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0022, aggregated August 25, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools