Operation DreamJob is a threat campaign observed in recent reporting that leverages Matrix Push C2 to control browser-targeted malware.
Overview
Operation DreamJob is a threat campaign observed in recent reporting that leverages Matrix Push C2 to control browser-targeted malware. It uses the Matrix chat protocol as a command-and-control channel to issue instructions to compromised browsers, signaling a shift toward decentralized C2 and a focus on the browser attack surface. This makes it notable for defenders as it demonstrates evolving, hard-to-detect C2 techniques that may bypass traditional HTTP/S-based controls.
Related Threat Clusters
-
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
Lazarus Hackers Target European Drone Manufacturers in Cyberespionage Campaign
The Lazarus hacking group, linked to North Korea, has initiated a cyberespionage campaign against European defense contractors involved in drone manufacturing. This operation aims to enhance North Korea's domestic drone…
3 articles · Updated January 26, 2026 -
Matrix Push C2 Framework Used for Browser Notification Attacks
Cybercriminals are utilizing the Matrix Push C2 framework to exploit browser notifications for distributing malicious links. This method involves social engineering tactics to trick users into allowing notifications,…
8 articles · Updated November 21, 2025 -
Matrix Push C2 Framework Exploits Browser Notifications for Cyberattacks
Cybercriminals are utilizing a new command-and-control platform known as Matrix Push C2 to execute phishing and malware attacks via web browsers. This framework leverages browser push notifications, tricking users into…
8 articles · Updated November 24, 2025
Recent Intelligence Reports
- ESET APT Activity Report Q4 2025–Q1 2026 — Welivesecurity · May 28, 2026
- Lazarus Hackers Actively Attacking European Drone Manufacturing Companies — Cybersecuritynews · January 26, 2026
- Hackers Adopt Matrix Push C2 for Browser — Gbhackers · November 21, 2025