EXECUTIVE SUMMARY
The cyber espionage group UNC2970, suspected to be linked to North Korea, has been identified employing tactics to target victims in critical infrastructure sectors. This group utilizes deceptive phishing lures masquerading as job openings from reputable companies, aiming to compromise senior- and manager-level employees in the energy and aerospace industries. The approach focuses on leveraging legitimate job descriptions, modified to align closely with the profiles of the targeted individuals, to enhance the chances of successful exploitation[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
The cyber espionage group UNC2970, suspected to be linked to North Korea, has been identified employing tactics to target victims in critical infrastructure sectors. This group utilizes deceptive phishing lures masquerading as job openings from reputable companies, aiming to compromise senior- and manager-level employees in the energy and aerospace industries. The approach focuses on leveraging legitimate job descriptions, modified to align closely with the profiles of the targeted individuals, to enhance the chances of successful exploitation[emaillocker id="1283"]
UNC2970's campaign involves delivering a password-protected ZIP archive via email and WhatsApp, which contains an encrypted PDF and a trojanized version of the open-source PDF viewer SumatraPDF. Upon execution, the malicious SumatraPDF loads a specially crafted dynamic-link library (DLL) that decrypts the embedded PDF, allowing the user to view the job description while simultaneously facilitating the deployment of the MISTPEN backdoor. The backdoor, which is a modified version of a legitimate Notepad++ plugin, allows remote execution of commands and downloads additional payloads. The infection chain highlights a meticulous process, including DLL search-order hijacking and the creation of a scheduled task to maintain persistence, demonstrating the group’s advanced capabilities.
The activities of UNC2970 underscore the ongoing threat posed by cyber espionage groups targeting critical infrastructure. By employing social engineering tactics and leveraging legitimate software, these actors can bypass traditional security measures, gaining access to sensitive information. Continuous vigilance and enhanced security awareness are essential to mitigate the risks associated with such cyber threats, especially as they increasingly exploit common tools and platforms to facilitate their malicious objectives.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1059 | Command and Scripting Interpreter |
| T1203 | Exploitation for Client Execution | |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Credential Access | T1003 | OS Credential Dumping |
| Discovery | T1046 | Network Service Discovery |
| Lateral Movement | T1021 | Remote Services |
| Collection | T1213 | Data from Information Repositories |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1486 | Data Encrypted for Impact |
REFERENCES:
The following reports contain further technical details:
https://cloud.google.com/blog/topics/threat-intelligence/unc2970-backdoor-trojanized-pdf-reader/