An Offer You Can Refuse: UNC2970 Backdoor Deployment Using Trojanized PDF Reader
ID: d76627a0-cfb5-555b-8cbd-817d80252533
STIX ID: report--d76627a0-cfb5-555b-8cbd-817d80252533
Feed Name: Google Cloud Threat Intelligence
Threat Score
Mandiant discovered UNC2970, a suspected North Korean-linked cyber espionage group that targets senior employees in U.S. critical infrastructure via tailored job-offer phishing. Victims receive password-protected ZIPs containing an encrypted PDF and a modified open-source SumatraPDF viewer, which is trojanized to execute a BURNBOOK launcher that installs the MISTPEN backdoor; Mandiant confirmed the modifications and notified SumatraPDF for awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
