Iranian "Dream Job" Campaign (TA455 / Charming Kitten) — SnailResin Loader & SlugResin Backdoor Targeting Aerospace, Aviation & Defense

Iranian "Dream Job" Campaign (TA455 / Charming Kitten) (TL-2026-0763), also tracked as Iranian Dream Job, is a high-severity advanced persistent threat campaign, first published 2026-06-10. It is attributed to TA455 (Iran) with medium confidence, affects Microsoft Windows (64-bit), maps to 18 MITRE ATT&CK techniques (T1021, T1027, T1036), and is covered by 9 detection rules and 22 indicators of compromise.

Key facts for TL-2026-0763

Threat ID
TL-2026-0763
Also known as
Iranian Dream Job, Iranian Dream Job Campaign, Dream Job (Iranian)
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-06-10
Last reviewed
2026-06-10
Attribution
TA455
Attribution confidence
MEDIUM
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
aerospace, aviation, defense, government
Target regions
Middle East, Israel, United Arab Emirates, Turkey, India, Albania
Detection rules
9
Indicators of compromise
22

Malware and tooling in Iranian "Dream Job" Campaign (TA455 / Charming Kitten)

Malware and tooling: BassBreaker, SlugResin, SnailResin, GitHub dead-drop resolver (account: msdnedgesupport)

TA455, an Iranian threat actor assessed as a subgroup of Charming Kitten / APT35 (tracked as UNC1549 by Mandiant and Yellow Dev 13 by PwC), has run a social-engineering "Dream Job" campaign since at least September 2023 against aerospace, aviation, and defense personnel. Fake recruiting sites (careers2find[.]com) and AI-generated LinkedIn recruiter personas deliver a ZIP containing SignedConnection.exe and a malicious secur32.dll that is DLL side-loaded as the SnailResin loader, activating the SlugResin backdoor (an updated BassBreaker variant). The toolset's deliberate overlap with North Korean Kimsuky/Lazarus "Dream Job" operations creates attribution ambiguity.

How Iranian "Dream Job" Campaign (TA455 / Charming Kitten) works

ClearSky Cyber Security published the "Iranian Dream Job" report on 2024-11-12, attributing an espionage campaign active since at least September 2023 to the Iranian threat actor TA455. TA455 is assessed to be a sub-cluster of Charming Kitten (APT35 / Mint Sandstorm / CALANQUE), tracked by Mandiant as UNC1549 and by PwC as Yellow Dev 13, and linked to Iran's Islamic Revolutionary Guard Corps (IRGC). The campaign targets the aerospace, aviation, and defense sectors with a particular focus on Israel, the United Arab Emirates, Turkey, India, and possibly Albania.

The operation borrows the well-known "Dream Job" social-engineering playbook. TA455 operators impersonate recruiters using fake LinkedIn personas decorated with AI-generated profile photographs and stolen identities of real individuals. Victims are engaged through LinkedIn messaging and a fraudulent recruitment portal, careers2find[.]com, fronted through Cloudflare to obscure the true hosting location. The site (and accompanying PDF "instructions") guide the target through downloading a ZIP archive that mixes benign job-related documents with a signed executable, SignedConnection.exe, and a malicious secur32.dll.

When SignedConnection.exe is launched, it side-loads the trojanized secur32.dll — the SnailResin loader (Trojan:Win64/SnailResin) — which decrypts and runs SlugResin (Backdoor:Win64/SlugResin), an updated version of the BassBreaker backdoor that grants remote access for follow-on credential theft, lateral movement, and secondary payload deployment. To resolve command-and-control infrastructure, SnailResin uses GitHub as a dead-drop resolver: it reads encoded C2 locations from seemingly innocuous GitHub accounts such as "msdnedgesupport", then communicates with backend infrastructure (e.g., xboxapicenter[.]com) while blending into the traffic of trusted services including GitHub, Cloudflare, and Microsoft Azure.

The campaign's most notable analytic feature is intentional tradecraft overlap with North Korean "Dream Job" operations (Lazarus/Kimsuky), which ClearSky assesses may be deliberate false-flag/attribution-confusion or evidence of tool-sharing, complicating attribution for defenders.

MITRE ATT&CK techniques used in TL-2026-0763

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1574 Hijack Execution Flow

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer

Execution

T1204 User Execution

defense-impairment

T1553 Subvert Trust Controls

Credential Access

T1555 Credentials from Password Stores

Initial Access

T1566 Phishing

stealth

T1574 Hijack Execution Flow

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains

Affected products and versions in Iranian "Dream Job" Campaign (TA455 / Charming Kitten)

  • Microsoft — Windows (64-bit)
    Vulnerable versions: targeted endpoints running side-loaded secur32.dll
  • LinkedIn — LinkedIn (social engineering vector — recruiter personas)
    Vulnerable versions: N/A — abused legitimate platform

Remediation for Iranian "Dream Job" Campaign (TA455 / Charming Kitten)

Immediate actions

  • Block careers2find[.]com and xboxapicenter[.]com at web/DNS proxies and perimeter
  • Block the C2 IPs 185.186.244.130, 89.221.225.249, and 77.91.74.171 at the firewall
  • Hunt for SignedConnection.exe and side-loaded secur32.dll outside System32, and for the listed SHA-256/SHA-1/MD5 hashes across the fleet
  • Alert on outbound requests to GitHub accounts used as dead-drop resolvers (e.g., msdnedgesupport) from non-developer hosts

Workarounds

  • Configure Windows to prefer KnownDLLs and safe DLL search order; block DLL loads from the same directory as user-downloaded executables
  • Strip or quarantine executables and DLLs from inbound ZIP archives at the mail/web gateway

Longer-term hardening

  • Deploy EDR with behavioral detection for DLL side-loading and unsigned/relocated secur32.dll loads
  • Enforce application allow-listing (WDAC/AppLocker) to prevent execution of ZIP-delivered binaries from user-writable paths
  • Security-awareness training focused on LinkedIn recruiter lures and unsolicited 'dream job' offers for aerospace/defense staff
  • Restrict and monitor egress to code-hosting/cloud services from sensitive segments; treat GitHub/Cloudflare/Azure traffic as in-scope for inspection

Weaknesses (CWE) in Iranian "Dream Job" Campaign (TA455 / Charming Kitten)

CWE-427, CWE-426

Timeline of Iranian "Dream Job" Campaign (TA455 / Charming Kitten)

  • TA455 begins the Iranian "Dream Job" campaign, targeting aerospace, aviation, and defense personnel via fake recruiting sites and LinkedIn personas (assessed start: at least September 2023).
  • Fake recruitment portal careers2find[.]com stood up behind Cloudflare; AI-generated LinkedIn recruiter personas created to engage targets.
  • ClearSky observes a LinkedIn recruiter account used by the actor created roughly four months prior; at least two additional TA455-generated recruiter personas identified.
  • Victims delivered ZIP archives containing SignedConnection.exe and malicious secur32.dll; DLL side-loading executes the SnailResin loader, activating the SlugResin backdoor.
  • SnailResin observed using GitHub accounts (e.g., msdnedgesupport) as dead-drop resolvers to obtain encoded C2 locations, blending into GitHub/Cloudflare/Azure traffic.
  • The Hacker News reports on the campaign — "Iranian Hackers Use 'Dream Job' Lures to Deploy SnailResin Malware in Aerospace Attacks" — summarizing ClearSky's findings on the SnailResin/SlugResin chain and GitHub dead-drop C2.
  • ClearSky Cyber Security publishes the "Iranian Dream Job" report (Ver 1.1), detailing TA455 attribution, SnailResin/SlugResin tooling, IOCs, and overlap with North Korean Dream Job operations.
  • Sector ISAC and threat-advisory outlets (RH-ISAC, Rewterz, Infosecurity Magazine) disseminate the TA455 "Dream Job" IOCs and TTPs to aviation/defense defenders, flagging the campaign as actively targeting critical industries.
  • Follow-on reporting tracks UNC1549/TA455 expanding LinkedIn job-lure operations into telecom targets with MINIBIKE malware, confirming a persistent operational pattern.

Sources cited for Iranian "Dream Job" Campaign (TA455 / Charming Kitten)

More in apt

Detection coverage for TL-2026-0763

As of 2026-06-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0763 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats