MISTPEN is a backdoor malware family associated with North Korea-linked espionage activity, including campaigns attributed to UNC2970 and Lazarus Group/Operation DreamJob. It has been used against victims in energy, aerospace, defense, nuclear-related, cryptocurrency, and broader critical infrastructure contexts, with reporting specifically noting targeting of U.S. critical infrastructure and European defense-related organizations.
Observed delivery commonly relies on recruiter- or job-themed social engineering. In one documented UNC2970 campaign, victims were contacted over email and WhatsApp and sent a password-protected ZIP archive posing as a job description. The archive contained an encrypted PDF and a trojanized older version of SumatraPDF; opening the lure ultimately launched the BURNBOOK loader, which delivered the MISTPEN backdoor. Separate Lazarus/Operation DreamJob reporting describes delivery through trojanized VNC software, malicious compressed ISO/ZIP archives, DLL side-loading via a malicious vnclang.dll, and other trojanized open-source software.
MISTPEN functions as a lightweight backdoor used for cyber espionage and payload delivery. Reporting states it can fetch additional payloads from command-and-control infrastructure; in one observed intrusion it retrieved RollMid and a new LPEClient variant under a random media.dat filename. It has been linked to compromised WordPress-based web servers running PHP services as C2 infrastructure. MISTPEN is described as relatively new public Lazarus tooling documented in 2024, and later reporting assesses with medium confidence that CookiePlus may be its successor based on shared plugin-style disguises and operational similarities.
High-confidence associations in the provided content include use alongside BURNBOOK, RollMid, LPEClient, CookieTime, Charamel Loader, ServiceChanger, and CookiePlus. The content also notes that Mandiant stated the SumatraPDF-related campaign did not involve a compromise of SumatraPDF and was not due to an inherent SumatraPDF vulnerability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Although we have not been able to obtain the malicious vnclang.dll, we classified it as a loader of the MISTPEN malware... According to our telemetry, in our particular case, MISTPEN ultimately fetched an additional payload... The first payload turned out to be RollMid... The second was identified as a new LPEClient variant.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The PDF file has been encrypted and can only be opened with the included trojanized version of SumatraPDF to ultimately deliver MISTPEN backdoor via BURNBOOK launcher. Mandiant observed UNC2970 modify the open source code of an older SumatraPDF version as part of this campaign.
The second is by distributing trojanized remote access tools such as VNC or PuTTY to convince the targets to connect to a specific server for a skills assessment.
Mandiant discovered additional phishing lures masquerading as an energy company and as an entity in the aerospace industry to target victims in these verticals.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MISTPEN is a malware deployed by Lazarus Group in targeted spear-phishing campaigns, primarily for data theft and espionage.
Backdoor malware referenced as being delivered via a WhatsApp job lure in an Operation DreamJob campaign targeting Europe.
Backdoor used in an intrusion chain associated with Operation DreamJob; observed using compromised SharePoint/WordPress resources for C2 infrastructure.
Referenced as a comparable loader family (per Mandiant) that BinMergeLoader is said to mirror; included here because it is a distinct named malware/tool mentioned in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.