logo

An Offer You Can Refuse: UNC2970 Backdoor Deployment Using Trojanized PDF Reader

ID: d76627a0-cfb5-555b-8cbd-817d80252533

STIX ID: report--d76627a0-cfb5-555b-8cbd-817d80252533

Feed Name: Google Cloud Threat Intelligence

Threat Score
88/100

Date Published: 2024-09-17

Date Updated: 2026-04-27

Author: Mandiant

...
...

Mandiant discovered UNC2970, a suspected North Korean-linked cyber espionage group that targets senior employees in U.S. critical infrastructure via tailored job-offer phishing. Victims receive password-protected ZIPs containing an encrypted PDF and a modified open-source SumatraPDF viewer, which is trojanized to execute a BURNBOOK launcher that installs the MISTPEN backdoor; Mandiant confirmed the modifications and notified SumatraPDF for awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.