Threat Advisory

UNC2970 Group Targets Critical Infrastructure with MISTPEN Backdoor Phishing Techniques

Threat: Malware
Threat Actor Name: Lazarus Group
Threat Actor Type: State-Sponsored
Targeted Region: United States, United Kingdom, Netherlands, Cyprus, Sweden, Germany, Singapore, Hong Kong & Australia
Alias: Genie Spider, Labyrinth Chollima, UNC577, UNC2970, UNC4034, UNC4736, UNC4899, Zinc, DEV-0139, Diamond Sleet, Jade Sleet, TA404, ITG03, Hastati Group, Hidden Cobra, Black Alicanto, ATK 3, Dangerous Password, CryptoCore, Leery Turtle , CryptoMimic, Group 77, Whois Hacking Team, NewRomanic Cyber Army Team, Appleworm, APT-C-26, SectorA01, Guardians of Peace, Gods Apostles, Gods Disciples, TraderTraitor
Threat Actor Region: North Korea
Targeted Sector: Government & Defense, Technology & IT, Education Aerospace & Aviation, Education
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The cyber espionage group UNC2970, suspected to be linked to North Korea, has been identified employing tactics to target victims in critical infrastructure sectors. This group utilizes deceptive phishing lures masquerading as job openings from reputable companies, aiming to compromise senior- and manager-level employees in the energy and aerospace industries. The approach focuses on leveraging legitimate job descriptions, modified to align closely with the profiles of the targeted individuals, to enhance the chances of successful exploitation[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The cyber espionage group UNC2970, suspected to be linked to North Korea, has been identified employing tactics to target victims in critical infrastructure sectors. This group utilizes deceptive phishing lures masquerading as job openings from reputable companies, aiming to compromise senior- and manager-level employees in the energy and aerospace industries. The approach focuses on leveraging legitimate job descriptions, modified to align closely with the profiles of the targeted individuals, to enhance the chances of successful exploitation[emaillocker id="1283"]

UNC2970's campaign involves delivering a password-protected ZIP archive via email and WhatsApp, which contains an encrypted PDF and a trojanized version of the open-source PDF viewer SumatraPDF. Upon execution, the malicious SumatraPDF loads a specially crafted dynamic-link library (DLL) that decrypts the embedded PDF, allowing the user to view the job description while simultaneously facilitating the deployment of the MISTPEN backdoor. The backdoor, which is a modified version of a legitimate Notepad++ plugin, allows remote execution of commands and downloads additional payloads. The infection chain highlights a meticulous process, including DLL search-order hijacking and the creation of a scheduled task to maintain persistence, demonstrating the group’s advanced capabilities.

The activities of UNC2970 underscore the ongoing threat posed by cyber espionage groups targeting critical infrastructure. By employing social engineering tactics and leveraging legitimate software, these actors can bypass traditional security measures, gaining access to sensitive information. Continuous vigilance and enhanced security awareness are essential to mitigate the risks associated with such cyber threats, especially as they increasingly exploit common tools and platforms to facilitate their malicious objectives.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
Execution T1059 Command and Scripting Interpreter
T1203 Exploitation for Client Execution
 Persistence  T1547 Boot or Logon Autostart Execution
Defense Evasion T1027 Obfuscated Files or Information
 Credential Access T1003 OS Credential Dumping
 Discovery T1046 Network Service Discovery
Lateral Movement T1021 Remote Services
Collection  T1213 Data from Information Repositories
 Exfiltration T1041 Exfiltration Over C2 Channel
 Impact T1486 Data Encrypted for Impact

REFERENCES:

The following reports contain further technical details:
https://cloud.google.com/blog/topics/threat-intelligence/unc2970-backdoor-trojanized-pdf-reader/

[/emaillocker]
crossmenu