Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management

12/6/2018
09:35 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

North Korean-Backed Group Suspected of 'Stolen Pencil' Campaign

The ASERT Team at NetScout has published a report that details a campaign dubbed "Stolen Pencil," which targeted universities and other academic groups. A North Korean-backed group is suspected of starting it.

A new campaign, possibly with backing from North Korea, is targeting universities and other academic institutions using spear phishing techniques, as well as a malicious Google Chrome extension, to gain a foothold inside various networks, according to new research released this week.

In a blog post published December 5, the ASERT Team at NetScout offers details about the campaign, which it calls "Stolen Pencil." It not clear what the motivation is behind this advanced persistent threat (APT), but institutions in the US and South Korea have been targeted.

"We've identified four universities based in the United States and one non-profit institution based in Asia we're certain have been targeted," ASERT Team researchers told Security Now in an email. "These might be just the tip of the iceberg. There are no indications of data theft, which is why the motivation behind the campaign remains unknown."

The report did note that many of the victims had backgrounds in biomedical engineering and research.

The group behind Stolen Pencil appears to use spear phishing techniques to lure victims to a specific website that contains a PDF document, which houses a malicious Google Chrome extension. If a person clicks the link and downloads the extension, the attackers can gain access to the network.

Once inside, the attackers use "living off the land," tools to spread through the network, including Microsoft's Remote Desktop Protocol (RDP), as opposed to a remote access Trojan or RAT. After establishing a presence, the group continues to look for more passwords and access, as well as deploying malware, such as keyloggers.

As the group moved around the network, the ASERT researchers found that the threat actors used two specific tools. The first, called MECHANICAL, is used for cryptojacking, specifically changing the wallet addresses of Ethereum cryptocurrency. The other tool is GREASE, which helps circumvent firewall rules.

Researchers found that compromised or stolen certificates were used to sign files where these tool sets were used.

In their email, the researchers noted:

The tools were almost certainly custom written. MECHANICAL is a keylogger, but also hijacks Ethereum transactions and sends the cryptocurrency to a specific wallet. GREASE adds an administrative account with a specific password. It’s possible they reused code snippets found online, but we haven't found any overlapping binary or source code signatures in anything publicly available.

The use of the cryptojacker, along with other evidence, such as English-to-Korean translator and an attacker changing someone's keyboard to Korean, points to North Korea as the sponsor of such a campaign. However, the researchers noted that a specific link could not be established.

"While we don't have any indication it is linked to a publicly reported DPRK [North Korea] actor group, the TTPs [Tools, Techniques, and Procedures] are similar to other campaigns and activity (i.e. the open source tools, the target types, the credential theft, the Ethereum cryptojacking, Korean keyboard/language settings, etc)," the researchers wrote in their email.

Earlier this year, Kaspersky Lab published a report that found phishing attacks against universities and school have been on the increase. The company found over 130 institutions in 16 different countries were targeted by these various phishing campaigns. (See Multiple Phishing Attacks Target Top Universities.)

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Manchester United Suffers Cyberattack
Dark Reading Staff 11/23/2020
As 'Anywhere Work' Evolves, Security Will Be Key Challenge
Robert Lemos, Contributing Writer,  11/23/2020
Cloud Security Startup Lightspin Emerges From Stealth
Kelly Sheridan, Staff Editor, Dark Reading,  11/24/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-20934
PUBLISHED: 2020-11-28
An issue was discovered in the Linux kernel before 5.2.6. On NUMA systems, the Linux fair scheduler has a use-after-free in show_numa_stats() because NUMA fault statistics are inappropriately freed, aka CID-16d51a590a8c.
CVE-2020-29368
PUBLISHED: 2020-11-28
An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.
CVE-2020-29369
PUBLISHED: 2020-11-28
An issue was discovered in mm/mmap.c in the Linux kernel before 5.7.11. There is a race condition between certain expand functions (expand_downwards and expand_upwards) and page-table free operations from an munmap call, aka CID-246c320a8cfe.
CVE-2020-29370
PUBLISHED: 2020-11-28
An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71.
CVE-2020-29371
PUBLISHED: 2020-11-28
An issue was discovered in romfs_dev_read in fs/romfs/storage.c in the Linux kernel before 5.8.4. Uninitialized memory leaks to userspace, aka CID-bcf85fcedfdd.