In an alarming development, a North Korean cyberespionage group has targeted employees from the aerospace and energy industries with fake job offers. According to Mandiant, the hackers use email and WhatsApp messages to get their victims to click on a link that installs backdoor malware on their devices.
Important findings
- The group, known as UNC2970, has targeted employees of companies such as BAE Systems.
- The attackers use custom job descriptions stored in a malicious archive.
- The malware they use is called MISTPEN and is a modified version of a Notepad++ plugin.
The Tactics of Attackers
Mandiant reported that the attackers first contacted the victims via email and then moved the conversation to WhatsApp. There, detailed job descriptions were sent, which were tailored specifically to the role of the victim. These descriptions were in PDF format and could only be opened with a Trojan version of SumatraPDF contained in the archive.
The group has used LinkedIn for similar phishing attacks in the past. In March 2023, there were reports that UNC2970 posed as a recruiter for renowned media organizations to get victims to open malicious files.
Technical Details of the Malware
In the recent campaign, the group used older versions of SumatraPDF to spread the backdoor malware MISTPEN. This malware is activated by a modified DLL file that acts as a launcher. The attackers did not use a direct exploit in SumatraPDF, but inserted a thread into the DllMain function to execute malicious code.
The malware uses a legitimate DLL file to load another malicious DLL that runs after a system reboot. Newer versions of SumatraPDF prevent users from loading modified versions of the legitimate DLL, forcing attackers to use older versions.
Increasing Threat from North Korean Attackers
North Korean cyberattacks against Western organizations have increased in recent years, especially since Kim Jong Un announced plans to modernize the country’s military and industry. In June 2024, several security agencies, including the National Intelligence Service of South Korea and the FBI, warned of targeted attacks on the defense, aviation and energy sectors.
The UNC2970 group has significant overlap with other North Korean hacking groups, suggesting that they share resources and malware tools among themselves. These attacks are part of a broader strategy to steal Western technologies and advance the regime’s military ambitions.
Conclusion
Current developments highlight the need for companies in the aerospace and energy sectors to strengthen their security arrangements. The threat of North Korean cyberattacks remains high and it is crucial that employees are informed about the risks of phishing and other cyberattacks.
Sources
- Fake Job Lures Target Employees of Aerospace, Energy Firms, BankInfoSecurity.



