Malware
MISTPEN
According to Mandiant, MISTPEN is a lightweight backdoor written in C whose main functionality is to download and execute Portable Executable (PE) files. The backdoor is a modification of the open-source Notepad++ binhex plugin v2.0.0.1 where the creation of a thread that executes the malicious code has been added to the DllMain function.
Indicators of Compromise 7
MITRE ATT&CK TTPs 9
T1055 T1071.001 T1085 T1090 T1134 T1203 T1218 T1480 T1548
Process Injection
Defense Evasion
Web Protocols
Command And Control
T1085
Proxy
Command And Control
Access Token Manipulation
Defense Evasion
Exploitation for Client Execution
Execution
System Binary Proxy Execution
Defense Evasion
Execution Guardrails
Defense Evasion
Abuse Elevation Control Mechanism
Privilege Escalation