BURNBOOK is a launcher/loader malware used to deliver the MISTPEN backdoor. Reporting links it to suspected North Korea–nexus activity, including UNC2970 and broader Lazarus Group Operation Dream Job tradecraft. In observed campaigns, targets were approached with recruiter- or job-themed social engineering over email, LinkedIn, or WhatsApp, including lures tailored to senior and manager-level employees in sectors such as defense, manufacturing, chemical, aerospace, technology, energy, and other U.S. critical infrastructure verticals. A documented infection chain used a password-protected ZIP archive masquerading as a job description package; the archive contained an encrypted PDF and a trojanized version of SumatraPDF based on an older modified open-source release. The encrypted PDF could only be opened with the included trojanized viewer, which then launched BURNBOOK to ultimately deliver MISTPEN. Once executed, BURNBOOK launches MISTPEN, a lightweight backdoor that communicates with command-and-control servers to download and execute additional malicious payloads. The reporting explicitly states this activity was not due to a compromise of SumatraPDF and did not involve an inherent SumatraPDF vulnerability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The PDF file has been encrypted and can only be opened with the included trojanized version of SumatraPDF to ultimately deliver MISTPEN backdoor via BURNBOOK launcher.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The PDF file has been encrypted and can only be opened with the included trojanized version of SumatraPDF to ultimately deliver MISTPEN backdoor via BURNBOOK launcher. Mandiant observed UNC2970 modify the open source code of an older SumatraPDF version as part of this campaign.
Mandiant discovered additional phishing lures masquerading as an energy company and as an entity in the aerospace industry to target victims in these verticals.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BURNBOOK is a malware used by Lazarus Group in social engineering campaigns targeting job seekers in various industries, aiming to collect sensitive data and facilitate further compromise.
Loader used in an intrusion chain associated with Operation DreamJob; observed alongside MISTPEN and using compromised SharePoint/WordPress resources for C2.
Dropper malware used to launch secondary payloads such as MISTPEN.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.