Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management

12/6/2018
09:35 AM
Scott Ferguson
Scott Ferguson
News Analysis-Security Now
50%
50%

North Korean-Backed Group Suspected of 'Stolen Pencil' Campaign

The ASERT Team at NetScout has published a report that details a campaign dubbed "Stolen Pencil," which targeted universities and other academic groups. A North Korean-backed group is suspected of starting it.

A new campaign, possibly with backing from North Korea, is targeting universities and other academic institutions using spear phishing techniques, as well as a malicious Google Chrome extension, to gain a foothold inside various networks, according to new research released this week.

In a blog post published December 5, the ASERT Team at NetScout offers details about the campaign, which it calls "Stolen Pencil." It not clear what the motivation is behind this advanced persistent threat (APT), but institutions in the US and South Korea have been targeted.

"We've identified four universities based in the United States and one non-profit institution based in Asia we're certain have been targeted," ASERT Team researchers told Security Now in an email. "These might be just the tip of the iceberg. There are no indications of data theft, which is why the motivation behind the campaign remains unknown."

(Source: Pixabay)
(Source: Pixabay)

The report did note that many of the victims had backgrounds in biomedical engineering and research.

The group behind Stolen Pencil appears to use spear phishing techniques to lure victims to a specific website that contains a PDF document, which houses a malicious Google Chrome extension. If a person clicks the link and downloads the extension, the attackers can gain access to the network.

Once inside, the attackers use "living off the land," tools to spread through the network, including Microsoft's Remote Desktop Protocol (RDP), as opposed to a remote access Trojan or RAT. After establishing a presence, the group continues to look for more passwords and access, as well as deploying malware, such as keyloggers.

As the group moved around the network, the ASERT researchers found that the threat actors used two specific tools. The first, called MECHANICAL, is used for cryptojacking, specifically changing the wallet addresses of Ethereum cryptocurrency. The other tool is GREASE, which helps circumvent firewall rules.

Researchers found that compromised or stolen certificates were used to sign files where these tool sets were used.

Certificate used to sign MECHANICAL/GREASE\r\n(Source: NetScout)\r\n
Certificate used to sign MECHANICAL/GREASE
\r\n(Source: NetScout)\r\n

In their email, the researchers noted:

The tools were almost certainly custom written. MECHANICAL is a keylogger, but also hijacks Ethereum transactions and sends the cryptocurrency to a specific wallet. GREASE adds an administrative account with a specific password. It’s possible they reused code snippets found online, but we haven't found any overlapping binary or source code signatures in anything publicly available.

The use of the cryptojacker, along with other evidence, such as English-to-Korean translator and an attacker changing someone's keyboard to Korean, points to North Korea as the sponsor of such a campaign. However, the researchers noted that a specific link could not be established.

"While we don't have any indication it is linked to a publicly reported DPRK [North Korea] actor group, the TTPs [Tools, Techniques, and Procedures] are similar to other campaigns and activity (i.e. the open source tools, the target types, the credential theft, the Ethereum cryptojacking, Korean keyboard/language settings, etc)," the researchers wrote in their email.

Earlier this year, Kaspersky Lab published a report that found phishing attacks against universities and school have been on the increase. The company found over 130 institutions in 16 different countries were targeted by these various phishing campaigns. (See Multiple Phishing Attacks Target Top Universities.)

Related posts:

— Scott Ferguson is the managing editor of Light Reading and the editor of Security Now. Follow him on Twitter @sferguson_LR.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises are Attacking the Cybersecurity Problem
Concerns over supply chain vulnerabilities and attack visibility drove some significant changes in enterprise cybersecurity strategies over the past year. Dark Reading's 2021 Strategic Security Survey showed that many organizations are staying the course regarding the use of a mix of attack prevention and threat detection technologies and practices for dealing with cyber threats.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-42258
PUBLISHED: 2021-10-22
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include ...
CVE-2020-28968
PUBLISHED: 2021-10-22
Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username input field.
CVE-2020-28969
PUBLISHED: 2021-10-22
Aplioxio PDF ShapingUp 5.0.0.139 contains a buffer overflow which allows attackers to cause a denial of service (DoS) via a crafted PDF file.
CVE-2020-36485
PUBLISHED: 2021-10-22
Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted JPEG file.
CVE-2020-36486
PUBLISHED: 2021-10-22
Swift File Transfer Mobile v1.1.2 and below was discovered to contain a cross-site scripting (XSS) vulnerability via the 'path' parameter of the 'list' and 'download' exception-handling.