#STOLENPENCIL

Incident/Operation

2018-12-05 • STOLEN PENCIL Campaign Targets Academia

STOLEN PENCIL is an APT campaign active since at least May 2018 against universities, with many identified victims working in biomedical engineering. The operators, assessed as possibly originating from North Korea, sent spear-phishing emails that opened lure documents and prompted installation of a malicious Chrome extension. After access, they relied on built-in Windows administration features and commercial tools, used Remote Desktop Protocol rather than a custom backdoor, and harvested credentials from process memory, browsers, network traffic, and keyloggers to maintain persistence; the ultimate objective and whether data was stolen remained unclear.

Tagged Reports

« Back