MISTPEN
- Malware type
- backdoor
- Profile updated
- 2026-07-07 14:51:14
Targeted industries: technology-and-telecommunications
Context
According to Mandiant, MISTPEN is a lightweight backdoor written in C whose main functionality is to download and execute Portable Executable (PE) files. The backdoor is a modification of the open-source Notepad++ binhex plugin v2.0.0.1 where the creation of a thread that executes the malicious code has been added to the DllMain function.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Mistpen_Auto (yara-rule)
Reports & references
- orangecyberdefense.com — A Pain In The Mist Navigating Operation Dreamjobs Arsenal (report)
- cloud.google.com — Unc2970 Backdoor Trojanized Pdf Reader (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Mistpen (report)
- Kaspersky — 115059 (report)