#MISTPEN

Malware/Tool

2024-09-17 • An Offer You Can Refuse: UNC2970 Backdoor Deployment Using Trojanized PDF Reader

MISTPEN is a lightweight Windows backdoor used in North Korea-linked UNC2970 operations to deliver additional payloads and maintain access to compromised systems. It has been deployed through job-themed lures containing a trojanized PDF viewer, with the BURNBOOK launcher decrypting and loading MISTPEN while displaying a legitimate-looking document. The malware can download and execute Portable Executable files in memory, collect host and process information through modular components, capture screenshots, and exchange encrypted data through Microsoft Graph and attacker-controlled OneDrive resources. Later campaigns paired it with privilege-escalation tooling and additional Lazarus backdoors.

Tagged Reports

« Back