#MISTPEN
Our analysis covers updated #BURNBOOK and #MISTPEN variants, that feature slight changes in their main routines and C2 loop.
UNC2970 relied on compromised infrastructure on SharePoint and WordPress, aligning with previous findings.
November 20, 2025 at 2:37 PM
"A Pain in the Mist: Navigating Operation DreamJob’s arsenal" published by OrangeCyberdefense. #DreamJob, #MISTPEN, #UNC2970, #DPRK, #CTI https://www.orangecyberdefense.com/global/blog/cert-news/a-pain-in-the-mist-navigating-operation-dreamjobs-arsenal
November 21, 2025 at 1:30 PM
The Lazarus group has evolved its infection chain, utilizing both old and new malware in a recent attack campaign targeting employees in defense and aerospace sectors through fake job offers, showcasing their adaptive tactics. #CyberSecurity #LazarusGroup securelist.com/lazarus-new-...
Lazarus targets nuclear-related organization with new malware
Lazarus targets employees of a nuclear-related organization with a bunch of malware, such as MISTPEN, LPEClient, RollMid, CookieTime and a new modular backdoor CookiePlus.
securelist.com
December 20, 2024 at 6:58 AM
“Lazarus group evolves its infection chain with old and new malware” #threatintel #cybersecurity
securelist.com/lazarus-new-...
Lazarus targets nuclear-related organization with new malware
Lazarus targets employees of a nuclear-related organization with a bunch of malware, such as MISTPEN, LPEClient, RollMid, CookieTime and a new modular backdoor CookiePlus.
securelist.com
December 24, 2024 at 1:02 PM
Lazarus-linked Operation Dream Job hit defense firms in Europe and India with trojanized PDF viewers, spear-phishing, and new FudModule exploits, including CVE-2026-68820 and Roundcube abuse. #Lazarus #India #Europe
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
Check Point Research tracked a long-running Operation Dream Job campaign linked to Lazarus, with a latest wave targeting defense organizations in Europe and India using trojanized PDF viewers, spear-phishing, and compromised web infrastructure. The campaign deployed SecurityPDF, Troy, MISTPEN, RelayShell, and a new FudModule variant exploiting CVE-2026-68820 while also abusing Roundcube servers via CVE-2025-49113. #OperationDreamJob #Lazarus #SecurityPDF #Troy #MISTPEN #RelayShell #FudModule #CVE-2026-68820 #CVE-2025-49113
www.hendryadrian.com
August 12, 2026 at 2:30 AM
The activity cluster is being tracked by Google-owned Mandiant under the moniker UNC2970, which it said overlaps with a threat group known as TEMP.Hermit, which is also broadly called Lazarus Group or Diamond Sleet (formerly Zinc). thehackernews.com/2024/09/nort...
North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware
North Korean hackers use job-themed phishing to deploy the MISTPEN backdoor, targeting global aerospace and energy sectors.
thehackernews.com
September 18, 2024 at 11:19 AM
ラザルスグループは新旧のマルウェアで感染チェーンを進化させている

Lazarus group evolves its infection chain with old and new malware #Kaspersky (Dec 19)

#Lazarus #LightlessCan #APTグループ #核関連組織 #サイバー攻撃
Lazarus targets nuclear-related organization with new malware
Lazarus targets employees of a nuclear-related organization with a bunch of malware, such as MISTPEN, LPEClient, RollMid, CookieTime and a new modular backdoor CookiePlus.
buff.ly
December 22, 2024 at 12:00 AM
Lazarus Group is exploiting a Windows zero-day to deploy the Troy backdoor against defense and aerospace targets via fake recruiter lures and trojanized software. #LazarusGroup #France #OperationDreamJob
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Lazarus Group is exploiting a recently patched Windows zero-day, CVE-2026-68820, to deliver a new backdoor called Troy against defense and aerospace targets in France, Germany, Brazil, and India through Operation Dream Job. The campaign uses fake recruiter lures, trojanized PDF software, and compromised legitimate sites and servers to spread MISTPEN, ForestTiger,...
www.hendryadrian.com
August 13, 2026 at 1:30 AM
Lazarus Group is exploiting Windows zero-day CVE-2026-68820 in fake job lures to hit defense, aerospace, and aviation targets with SYSTEM-level malware and data theft. #LazarusGroup #India #WindowsZeroDay
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
North Korean hackers linked to the Lazarus Group are abusing the newly patched Windows zero-day CVE-2026-68820 in fake job application lures to compromise defense, aerospace, and aviation targets. The campaign uses Mistpen, ForestTiger, Troy, SecurityPDF, and RelayShell to gain SYSTEM privileges, persist, and steal data through compromised web infrastructure. #LazarusGroup #CVE-2026-68820...
www.hendryadrian.com
August 12, 2026 at 10:15 AM
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
research.checkpoint.com
August 12, 2026 at 12:04 AM
The Lazarus Group has deployed new malware tools in their latest cyber-espionage campaigns targeting critical infrastructure and defense sectors.

securelist.com/lazarus-new-...
Lazarus targets nuclear-related organization with new malware
Lazarus targets employees of a nuclear-related organization with a bunch of malware, such as MISTPEN, LPEClient, RollMid, CookieTime and a new modular backdoor CookiePlus.
securelist.com
December 20, 2024 at 11:09 AM
North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware · The Hacker News
North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware
North Korean hackers use job-themed phishing to deploy the MISTPEN backdoor, targeting global aerospace and energy sectors.
thehackernews.com
September 19, 2024 at 8:03 PM
北朝鮮のハッカー、防衛技術者を偽の求人で誘いドローンの機密を窃取

北朝鮮と関係のある脅威アクターが、長期にわたるキャンペーン「Operation Dream Job」の一環として、防衛産業に従事する欧州企業を標的とした新たな攻撃の波に関与しているとされています。 「これらの企業の中には無人航空機(UAV)分野に深く関与している企業もあり、この作戦が北朝鮮によるドローンプログラム拡大の取り組みと関連している可能性が示唆されます」と、ESETのセキュリティ研究者Peter Kálnai氏とAlexis Rapin氏は、The Hacker Newsと共有したレポートで述べています。…
北朝鮮のハッカー、防衛技術者を偽の求人で誘いドローンの機密を窃取
北朝鮮と関係のある脅威アクターが、長期にわたるキャンペーン「Operation Dream Job」の一環として、防衛産業に従事する欧州企業を標的とした新たな攻撃の波に関与しているとされています。 「これらの企業の中には無人航空機(UAV)分野に深く関与している企業もあり、この作戦が北朝鮮によるドローンプログラム拡大の取り組みと関連している可能性が示唆されます」と、ESETのセキュリティ研究者Peter Kálnai氏とAlexis Rapin氏は、The Hacker Newsと共有したレポートで述べています。 このキャンペーンの最終的な目的は、ScoringMathTeaやMISTPENといったマルウェアファミリーを用いて、企業の独自情報や製造ノウハウを窃取することだと評価されています。スロバキアのサイバーセキュリティ企業であるESETは、2025年3月下旬からこのキャンペーンを観測していると述べています。 標的となった組織には、東南ヨーロッパの金属工学企業、中央ヨーロッパの航空機部品メーカー、中央ヨーロッパの防衛企業などが含まれています。 ScoringMathTea(別名ForestTiger)は、2023年初頭にESETによって、インドのテクノロジー企業やポーランドの防衛請負業者を標的としたサイバー攻撃との関連で観測されていました。一方、MISTPENは2024年9月にGoogle Mandiantによって、エネルギーや航空宇宙分野の企業を狙った侵入の一部として記録されています。ScoringMathTeaの最初の出現は2022年10月にさかのぼります。 Operation Dream Jobは、2020年にイスラエルのサイバーセキュリティ企業ClearSkyによって初めて明らかにされた、北朝鮮の著名なハッカー集団「Lazarus Group」(APT-Q-1、Black Artemis、Diamond Sleet(旧Zinc)、Hidden Cobra、TEMP.Hermit、UNC2970としても追跡)が展開する持続的な攻撃キャンペーンです。このハッカー集団は少なくとも2009年から活動していると考えられています。 これらの攻撃では、脅威アクターがContagious Interviewに類似したソーシャルエンジニアリング手法を利用し、標的となる人物に高収入の求人を持ちかけ、マルウェアに感染させるよう仕向けます。このキャンペーンはまた、DeathNote、NukeSped、Operation In(ter)ception、Operation North Starとして追跡されているクラスターとも重複が見られます。 「主要な手口は、高収入だが偽の求人とマルウェアの組み合わせです。標的は求人内容が記載されたダミー文書と、それを開くためのトロイの木馬化されたPDFリーダーを受け取ります」とESETの研究者は述べています。 攻撃の連鎖はバイナリの実行につながり、これが悪意のあるDLLをサイドロードしてScoringMathTeaおよびBinMergeLoaderという高度なダウンローダーを展開します。BinMergeLoaderはMISTPENと同様に機能し、Microsoft Graph APIやトークンを使って追加のペイロードを取得します。 別の感染経路では、未知のドロッパーが2つの中間ペイロードを配布し、最初のペイロードが後者をロードすることで、最終的にScoringMathTeaが展開されます。ScoringMathTeaは約40種類のコマンドをサポートし、感染したマシンを完全に制御できる高度なRATです。 「Lazarusはほぼ3年間、一貫した手口を維持しており、好んで使うメインペイロードであるScoringMathTeaを展開し、オープンソースアプリケーションをトロイの木馬化する類似の手法を用いています」とESETは述べています。「この予測可能でありながら効果的な戦略は、グループの身元や帰属を隠しきれないものの、十分な多様性を持たせることでセキュリティ検知を回避しています。」 翻訳元:
blackhatnews.tokyo
October 23, 2025 at 3:54 PM
North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware #cybersecurity #infosec #privacy #news thehackernews.com/20...
September 18, 2024 at 11:06 AM
#NorthKorean cyber-espionage group #UNC2970 is now targeting aerospace and energy sectors using job-themed phishing lures to deliver a new backdoor, MISTPEN.
thehackernews.com/2024/09/nort...
#cybersecurity #hacking #malware
North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware
North Korean hackers use job-themed phishing to deploy the MISTPEN backdoor, targeting global aerospace and energy sectors.
thehackernews.com
September 18, 2024 at 8:11 PM
Lazarus targets nuclear-related organization with new malware | Securelist securelist.com/lazarus-new-...
Lazarus targets nuclear-related organization with new malware
Lazarus targets employees of a nuclear-related organization with a bunch of malware, such as MISTPEN, LPEClient, RollMid, CookieTime and a new modular backdoor CookiePlus.
securelist.com
December 20, 2024 at 5:56 PM
North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware

#thehackersnews
North Korean Hackers Target Energy and Aerospace Industries with New MISTPEN Malware
North Korean hackers use job-themed phishing to deploy the MISTPEN backdoor, targeting global aerospace and energy sectors.
thehackernews.com
September 18, 2024 at 11:55 AM