#DreamLoader

Malware/Tool

2025-10-24 • From Dream Job to Malware: DreamLoaders in Lazarus’ Recent Campaign

DreamLoader is a collective label for several modular loaders used in Lazarus DreamJob activity rather than one uniform malware family. The set includes trojanized TightVNC, DLLs side-loaded by legitimate Windows executables, HideFirstLetter.dll, and TSVIPSrv.dll. Components decrypt Base64- or RC4-protected payloads, load them into memory, query Microsoft identity and Graph endpoints, and retrieve data from compromised SharePoint resources. TSVIPSrv.dll reads encrypted payloads from separate .mui files, allowing operators to change modules independently.

Tagged Reports

« Back