Stolen Pencil
0 incidentes
0 paises
0 sectores
apt KR Ultimo: -
Aliases: babyshark, kimjongrat
Stolen Pencil is an alias for Kimsuky, also known as APT43, Thallium, Black Banshee, and Velvet Chollima, a North Korea-linked cyber espionage group active since at least 2012. The group's primary motivation is intelligence gathering, focusing on geopolitical information related to foreign policy, national security, nuclear policy, and sanctions relevant to the North Korean regime. While initially targeting South Korean entities, their operations expanded globally, including academic institutions, government organizations, and defense-related sectors. The "Stolen Pencil" campaign specifically refers to their activities observed since May 2018, primarily targeting academic institutions for credential harvesting and intellectual property theft, particularly in biomedical engineering. What sets this group apart is its consistent evolution of tactics, techniques, and procedures (TTPs), moving from basic spear-phishing with off-the-shelf tools to more sophisticated methods like abusing legi