MISTPEN

Malware type
backdoor
Profile updated
2026-07-07 14:51:14

Targeted industries: technology-and-telecommunications

Context

According to Mandiant, MISTPEN is a lightweight backdoor written in C whose main functionality is to download and execute Portable Executable (PE) files. The backdoor is a modification of the open-source Notepad++ binhex plugin v2.0.0.1 where the creation of a thread that executes the malicious code has been added to the DllMain function.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Mistpen_Auto (yara-rule)

Reports & references

  • orangecyberdefense.com — A Pain In The Mist Navigating Operation Dreamjobs Arsenal (report)
  • cloud.google.com — Unc2970 Backdoor Trojanized Pdf Reader (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Mistpen (report)
  • Kaspersky — 115059 (report)

External references