#LCPDot

Malware/Tool

2021-01-28 • Internals of Lazarus Operation Dream Job

LCPDot is a Windows downloader used by Lazarus Group in Operation Dream Job. It was delivered through job-themed social engineering and executed as a large, timestomped DLL under ProgramData by a daily scheduled task using rundll32. The malware stores an RC4-encrypted configuration containing command-and-control URLs, registers the compromised host over HTTP, and requests a second-stage payload. It derives an RC4 key from a random 16-byte value, decrypts the received payload, loads it directly into memory, and executes it in a new thread.

Tagged Reports

« Back