Iranian "Dream Job" Campaign (TA455 / Charming Kitten) — SnailResin Loader & SlugResin Backdoor Targeting Aerospace, Aviation & Defense
Iranian "Dream Job" Campaign (TA455 / Charming Kitten) (TL-2026-0763), also tracked as Iranian Dream Job, is a high-severity advanced persistent threat campaign, first published 2026-06-10. It is attributed to TA455 (Iran) with medium confidence, affects Microsoft Windows (64-bit), maps to 18 MITRE ATT&CK techniques (T1021, T1027, T1036), and is covered by 9 detection rules and 22 indicators of compromise.
Key facts for TL-2026-0763
- Threat ID
- TL-2026-0763
- Also known as
- Iranian Dream Job, Iranian Dream Job Campaign, Dream Job (Iranian)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-06-10
- Last reviewed
- 2026-06-10
- Attribution
- TA455
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- aerospace, aviation, defense, government
- Target regions
- Middle East, Israel, United Arab Emirates, Turkey, India, Albania
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in Iranian "Dream Job" Campaign (TA455 / Charming Kitten)
Malware and tooling: BassBreaker, SlugResin, SnailResin, GitHub dead-drop resolver (account: msdnedgesupport)
TA455, an Iranian threat actor assessed as a subgroup of Charming Kitten / APT35 (tracked as UNC1549 by Mandiant and Yellow Dev 13 by PwC), has run a social-engineering "Dream Job" campaign since at least September 2023 against aerospace, aviation, and defense personnel. Fake recruiting sites (careers2find[.]com) and AI-generated LinkedIn recruiter personas deliver a ZIP containing SignedConnection.exe and a malicious secur32.dll that is DLL side-loaded as the SnailResin loader, activating the SlugResin backdoor (an updated BassBreaker variant). The toolset's deliberate overlap with North Korean Kimsuky/Lazarus "Dream Job" operations creates attribution ambiguity.
How Iranian "Dream Job" Campaign (TA455 / Charming Kitten) works
ClearSky Cyber Security published the "Iranian Dream Job" report on 2024-11-12, attributing an espionage campaign active since at least September 2023 to the Iranian threat actor TA455. TA455 is assessed to be a sub-cluster of Charming Kitten (APT35 / Mint Sandstorm / CALANQUE), tracked by Mandiant as UNC1549 and by PwC as Yellow Dev 13, and linked to Iran's Islamic Revolutionary Guard Corps (IRGC). The campaign targets the aerospace, aviation, and defense sectors with a particular focus on Israel, the United Arab Emirates, Turkey, India, and possibly Albania.
The operation borrows the well-known "Dream Job" social-engineering playbook. TA455 operators impersonate recruiters using fake LinkedIn personas decorated with AI-generated profile photographs and stolen identities of real individuals. Victims are engaged through LinkedIn messaging and a fraudulent recruitment portal, careers2find[.]com, fronted through Cloudflare to obscure the true hosting location. The site (and accompanying PDF "instructions") guide the target through downloading a ZIP archive that mixes benign job-related documents with a signed executable, SignedConnection.exe, and a malicious secur32.dll.
When SignedConnection.exe is launched, it side-loads the trojanized secur32.dll — the SnailResin loader (Trojan:Win64/SnailResin) — which decrypts and runs SlugResin (Backdoor:Win64/SlugResin), an updated version of the BassBreaker backdoor that grants remote access for follow-on credential theft, lateral movement, and secondary payload deployment. To resolve command-and-control infrastructure, SnailResin uses GitHub as a dead-drop resolver: it reads encoded C2 locations from seemingly innocuous GitHub accounts such as "msdnedgesupport", then communicates with backend infrastructure (e.g., xboxapicenter[.]com) while blending into the traffic of trusted services including GitHub, Cloudflare, and Microsoft Azure.
The campaign's most notable analytic feature is intentional tradecraft overlap with North Korean "Dream Job" operations (Lazarus/Kimsuky), which ClearSky assesses may be deliberate false-flag/attribution-confusion or evidence of tool-sharing, complicating attribution for defenders.
MITRE ATT&CK techniques used in TL-2026-0763
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1574 Hijack Execution Flow
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer
Execution
defense-impairment
Credential Access
T1555 Credentials from Password Stores
Initial Access
stealth
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains
Affected products and versions in Iranian "Dream Job" Campaign (TA455 / Charming Kitten)
- Microsoft — Windows (64-bit)
Vulnerable versions: targeted endpoints running side-loaded secur32.dll - LinkedIn — LinkedIn (social engineering vector — recruiter personas)
Vulnerable versions: N/A — abused legitimate platform
Remediation for Iranian "Dream Job" Campaign (TA455 / Charming Kitten)
Immediate actions
- Block careers2find[.]com and xboxapicenter[.]com at web/DNS proxies and perimeter
- Block the C2 IPs 185.186.244.130, 89.221.225.249, and 77.91.74.171 at the firewall
- Hunt for SignedConnection.exe and side-loaded secur32.dll outside System32, and for the listed SHA-256/SHA-1/MD5 hashes across the fleet
- Alert on outbound requests to GitHub accounts used as dead-drop resolvers (e.g., msdnedgesupport) from non-developer hosts
Workarounds
- Configure Windows to prefer KnownDLLs and safe DLL search order; block DLL loads from the same directory as user-downloaded executables
- Strip or quarantine executables and DLLs from inbound ZIP archives at the mail/web gateway
Longer-term hardening
- Deploy EDR with behavioral detection for DLL side-loading and unsigned/relocated secur32.dll loads
- Enforce application allow-listing (WDAC/AppLocker) to prevent execution of ZIP-delivered binaries from user-writable paths
- Security-awareness training focused on LinkedIn recruiter lures and unsolicited 'dream job' offers for aerospace/defense staff
- Restrict and monitor egress to code-hosting/cloud services from sensitive segments; treat GitHub/Cloudflare/Azure traffic as in-scope for inspection
Weaknesses (CWE) in Iranian "Dream Job" Campaign (TA455 / Charming Kitten)
CWE-427, CWE-426
Timeline of Iranian "Dream Job" Campaign (TA455 / Charming Kitten)
- TA455 begins the Iranian "Dream Job" campaign, targeting aerospace, aviation, and defense personnel via fake recruiting sites and LinkedIn personas (assessed start: at least September 2023).
- Fake recruitment portal careers2find[.]com stood up behind Cloudflare; AI-generated LinkedIn recruiter personas created to engage targets.
- ClearSky observes a LinkedIn recruiter account used by the actor created roughly four months prior; at least two additional TA455-generated recruiter personas identified.
- Victims delivered ZIP archives containing SignedConnection.exe and malicious secur32.dll; DLL side-loading executes the SnailResin loader, activating the SlugResin backdoor.
- SnailResin observed using GitHub accounts (e.g., msdnedgesupport) as dead-drop resolvers to obtain encoded C2 locations, blending into GitHub/Cloudflare/Azure traffic.
- The Hacker News reports on the campaign — "Iranian Hackers Use 'Dream Job' Lures to Deploy SnailResin Malware in Aerospace Attacks" — summarizing ClearSky's findings on the SnailResin/SlugResin chain and GitHub dead-drop C2.
- ClearSky Cyber Security publishes the "Iranian Dream Job" report (Ver 1.1), detailing TA455 attribution, SnailResin/SlugResin tooling, IOCs, and overlap with North Korean Dream Job operations.
- Sector ISAC and threat-advisory outlets (RH-ISAC, Rewterz, Infosecurity Magazine) disseminate the TA455 "Dream Job" IOCs and TTPs to aviation/defense defenders, flagging the campaign as actively targeting critical industries.
- Follow-on reporting tracks UNC1549/TA455 expanding LinkedIn job-lure operations into telecom targets with MINIBIKE malware, confirming a persistent operational pattern.
Sources cited for Iranian "Dream Job" Campaign (TA455 / Charming Kitten)
- Iranian "Dream Job" Campaign 11.24
- Iranian Dream Job campaign Ver 1.1 11/24 (full report PDF)
- Iranian Hackers Use "Dream Job" Lures to Deploy SnailResin Malware in Aerospace Attacks
- TA455's Iranian Dream Job Campaign Targets Aerospace with Malware
- Iranian Dream Job Campaign Targets Aerospace Industry with SnailResin Malware
- Iranian Cybercriminals Incorporate SnailResin Malware into Aerospace Attacks (Active IOCs)
- Iranian TA455 Initiates Dream Job Campaign to Target Aviation and Other Critical Industries
- UNC1549 Hacks Devices in Telecom Firms via LinkedIn Job Lures and MINIBIKE Malware
More in apt
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)
- Bitget Exchange Loses ~$351.6M (On-Chain: ~$356.9M) in Suspected North Korean (TraderTraitor) Backend Compromise and Authorization-Flow Abuse
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)
Detection coverage for TL-2026-0763
As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0763 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.