North Korean-Backed Group Suspected of 'Stolen Pencil' Campaign

The ASERT Team at NetScout has published a report that details a campaign dubbed "Stolen Pencil," which targeted universities and other academic groups. A North Korean-backed group is suspected of starting it.

Scott Ferguson, Managing Editor, Light Reading

December 6, 2018

3 Min Read

A new campaign, possibly with backing from North Korea, is targeting universities and other academic institutions using spear phishing techniques, as well as a malicious Google Chrome extension, to gain a foothold inside various networks, according to new research released this week.

In a blog post published December 5, the ASERT Team at NetScout offers details about the campaign, which it calls "Stolen Pencil." It not clear what the motivation is behind this advanced persistent threat (APT), but institutions in the US and South Korea have been targeted.

"We've identified four universities based in the United States and one non-profit institution based in Asia we're certain have been targeted," ASERT Team researchers told Security Now in an email. "These might be just the tip of the iceberg. There are no indications of data theft, which is why the motivation behind the campaign remains unknown."

(Source: Pixabay)

(Source: Pixabay)

The report did note that many of the victims had backgrounds in biomedical engineering and research.

The group behind Stolen Pencil appears to use spear phishing techniques to lure victims to a specific website that contains a PDF document, which houses a malicious Google Chrome extension. If a person clicks the link and downloads the extension, the attackers can gain access to the network.

Once inside, the attackers use "living off the land," tools to spread through the network, including Microsoft's Remote Desktop Protocol (RDP), as opposed to a remote access Trojan or RAT. After establishing a presence, the group continues to look for more passwords and access, as well as deploying malware, such as keyloggers.

As the group moved around the network, the ASERT researchers found that the threat actors used two specific tools. The first, called MECHANICAL, is used for cryptojacking, specifically changing the wallet addresses of Ethereum cryptocurrency. The other tool is GREASE, which helps circumvent firewall rules.

Researchers found that compromised or stolen certificates were used to sign files where these tool sets were used.

Certificate used to sign MECHANICAL/GREASE\r\n(Source: NetScout)\r\n

Certificate used to sign MECHANICAL/GREASE
\r\n(Source: NetScout)\r\n

In their email, the researchers noted:

"The tools were almost certainly custom written. MECHANICAL is a keylogger, but also hijacks Ethereum transactions and sends the cryptocurrency to a specific wallet. GREASE adds an administrative account with a specific password. It’s possible they reused code snippets found online, but we haven't found any overlapping binary or source code signatures in anything publicly available."

The use of the cryptojacker, along with other evidence, such as English-to-Korean translator and an attacker changing someone's keyboard to Korean, points to North Korea as the sponsor of such a campaign. However, the researchers noted that a specific link could not be established.

"While we don't have any indication it is linked to a publicly reported DPRK [North Korea] actor group, the TTPs [Tools, Techniques, and Procedures] are similar to other campaigns and activity (i.e. the open source tools, the target types, the credential theft, the Ethereum cryptojacking, Korean keyboard/language settings, etc)," the researchers wrote in their email.

Earlier this year, Kaspersky Lab published a report that found phishing attacks against universities and school have been on the increase. The company found over 130 institutions in 16 different countries were targeted by these various phishing campaigns. (See Multiple Phishing Attacks Target Top Universities.)

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Read more about:

Security Now

About the Author

Scott Ferguson

Managing Editor, Light Reading

Prior to joining Enterprise Cloud News, he was director of audience development for InformationWeek, where he oversaw the publications' newsletters, editorial content, email and content marketing initiatives. Before that, he served as editor-in-chief of eWEEK, overseeing both the website and the print edition of the magazine. For more than a decade, Scott has covered the IT enterprise industry with a focus on cloud computing, datacenter technologies, virtualization, IoT and microprocessors, as well as PCs and mobile. Before covering tech, he was a staff writer at the Asbury Park Press and the Herald News, both located in New Jersey. Scott has degrees in journalism and history from William Paterson University, and is based in Greater New York.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights