SumatraPDF is a legitimate, signed open-source PDF reader, not malware. The provided reporting describes multiple threat actors abusing trojanized or modified copies of older SumatraPDF versions as part of delivery chains, and explicitly states this was not a compromise of the SumatraPDF project and did not involve an inherent SumatraPDF vulnerability. In one campaign reported by Breakglass Intelligence, a legitimate signed SumatraPDF.exe v3.5.2 binary was paired with a malicious DWrite.dll for DLL side-loading after delivery via resume-themed spearphishing against HR departments; the malicious chain included steganographic payload extraction, BYOVD abuse of Adlice TrueSight truesight.sys to terminate security products, process hollowing into winlogon.exe, installation of a rogue root certificate, scheduled-task persistence, and HTTPS C2 to 157.250.202.215. In Microsoft reporting, Diamond Sleet was noted as using a similar method involving trojanized PuTTY and SumatraPDF. In Mandiant reporting, suspected North Korea–nexus UNC2970 modified the open-source code of an older SumatraPDF version and delivered it inside password-protected recruiter-themed ZIP archives so that an encrypted PDF could only be opened with the included trojanized viewer, ultimately delivering the MISTPEN backdoor via the BURNBOOK launcher against targets in U.S. critical infrastructure. High-confidence observables directly tied to the abuse include SumatraPDF.exe v3.5.2 signed by Krzysztof Kowalczyk and malicious side-loading via DWrite.dll.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mandiant observed UNC2970 modify the open source code of an older SumatraPDF version as part of this campaign. This is not a compromise of SumatraPDF, nor is there any inherent vulnerability in SumatraPDF.
Microsoft observed Diamond Sleet using a similar method – trojanized PuTTY and SumatraPDF
4 distinct techniques documented for this family, organized by ATT&CK tactic.
The PDF file has been encrypted and can only be opened with the included trojanized version of SumatraPDF to ultimately deliver MISTPEN backdoor via BURNBOOK launcher. Mandiant observed UNC2970 modify the open source code of an older SumatraPDF version as part of this campaign.
The starting point of the attack is a ZIP archive containing military-themed document lures to launch the rogue version of SumatraPDF, which is then used to display a decoy PDF document, while simultaneously retrieving encrypted shellcode from a staging server to launch AdaptixC2 Beacon.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate signed PDF reader abused as a DLL side-loading host to load the malicious DWrite.dll while presenting a benign PDF reader to the victim.
Legitimate PDF reader referenced as having been trojanized by Diamond Sleet as part of similar initial access tradecraft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.