Operation DreamJob — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 21, 2025
Last Seen
May 28, 2026

Operation DreamJob is a threat campaign observed in recent reporting that leverages Matrix Push C2 to control browser-targeted malware.

Overview

Operation DreamJob is a threat campaign observed in recent reporting that leverages Matrix Push C2 to control browser-targeted malware. It uses the Matrix chat protocol as a command-and-control channel to issue instructions to compromised browsers, signaling a shift toward decentralized C2 and a focus on the browser attack surface. This makes it notable for defenders as it demonstrates evolving, hard-to-detect C2 techniques that may bypass traditional HTTP/S-based controls.

Related Threat Clusters

Recent Intelligence Reports

  • ESET APT Activity Report Q4 2025–Q1 2026 — Welivesecurity · May 28, 2026
  • Lazarus Hackers Actively Attacking European Drone Manufacturing Companies — Cybersecuritynews · January 26, 2026
  • Hackers Adopt Matrix Push C2 for Browser — Gbhackers · November 21, 2025

CVSS v3.1 Breakdown