#BURNBOOK

Malware/Tool

2024-09-17 • An Offer You Can Refuse: UNC2970 Backdoor Deployment Using Trojanized PDF Reader

BURNBOOK is a C/C++ launcher embedded in a modified SumatraPDF DLL and used by UNC2970 in job-themed attacks. Victims received a password-protected archive containing an encrypted PDF lure and a trojanized PDF reader; opening the lure triggered the malicious DLL. BURNBOOK reads a key and nonce from the crafted PDF, uses ChaCha20 to decrypt embedded content, writes decrypted material to disk, and helps load the MISTPEN backdoor. The campaign targeted senior personnel in U.S. critical-infrastructure sectors.

Tagged Reports

« Back