Cyber Security News

UNC2970 Hackers Targeting Job Seekers with Weaponized PDF Files

Trojanized PDF readers are malicious software that are disguised as legitimate PDF viewing applications. 

They are primarily used by the threat actors to deliver malware by exploiting vulnerabilities in the PDF format and tricking users into executing malicious code.

Recently, cybersecurity analysts at Google Mandiant identified that UNC2970 hackers have been actively attacking job seekers using weaponized PDF readers.

In June 2024, Mandiant Managed Defense identified UNC2970, a suspected North Korean cyber espionage group targeting U.S. critical infrastructure sectors.

Decoding Compliance: What CISOs Need to Know – Join Free Webinar

Sophisticated Phishing Tactics

The group employs sophisticated phishing tactics, posing as recruiters and sending tailored job descriptions for senior-level positions. 

Their infection chain utilizes a password-protected ZIP archive containing an encrypted PDF and a trojanized version of “SumatraPDF” (v3.4.3 or earlier). 

When victims open the PDF using the modified application, it triggers the “BURNBOOK” launcher (a malicious libmupdf.dll) which decrypts the PDF using “ChaCha20” cipher with a “32-byte key” and “12-byte nonce.” 

BURNBOOK then loads the “MISTPEN” backdoor which is a modified Notepad++ plugin (binhex.dll), into the SumatraPDF.exe process via reflective loading, Mandiant said

For persistence, the malware creates a scheduled task named “Sumatra Launcher” in %APPDATA%\Microsoft\BDE UI Launcher, using “BdeUISrv.exe” and employing DLL search-order hijacking with a malicious “wtsapi32.dll.” 

The MISTPEN payload is re-encrypted and stored in %APPDATA%\Thumbs.ini for later execution. 

This technique allows UNC2970 to bypass security measures, targeting aerospace, energy, and nuclear sectors. 

The campaign doesn’t exploit any vulnerability in SumatraPDF but rather modifies its open-source code to deliver the malicious payload.

Infection lifecycle (Source – Mandiant)

MISTPEN is written in C, and its primary function is to download and execute Portable Executable (PE) files. 

The backdoor uses AES encryption with a specific 256-bit key to decrypt a token, which it then uses to access Microsoft Graph APIs. 

MISTPEN communicates over HTTPS with Microsoft endpoints, including login.microsoftonline.com and graph.microsoft.com. 

It supports various commands like:- 

  • ‘d’ for loading and executing PE payloads.
  • ‘e’ for termination.
  • ‘f’ for sleep functionality.
  • ‘g’ for updating its configuration.

The backdoor can read and write its settings to a file named “setup.bin” which allows persistent configuration. However, MISTPEN backdoor is often delivered alongside “BURNBOOK,” a trojanized PDF reader that employs DLL search order hijacking. 

While the “TEARPAGE” is another component that acts as a loader and uses ChaCha20 cipher from an encrypted blob in “%APPDATA%\Thumbs.ini” to decrypt the “MISTPEN.” 

This malware suite is linked with UNC2970, and this group uses job-themed phishing emails to target multinational companies across various sectors and countries.

Are You From SOC/DFIR Teams? - Try Advanced Malware and Phishing Analysis With ANY.RUN - 14-day free trial

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago