Overview 17 indicators
Stolen Pencil is a threat group likely originating from DPRK that has been active since at least May 2018. The group appears to have targeted academic institutions, but its motives remain unclear.
| domain | 15 | G0086-domain.txt |
| url | 1 | G0086.json |
| url_path | 1 | G0086.json |
Principal sources 3 reports
Ranked by how many of this actor's indicators each report brought in.
- 15asert.arbornetworks.com/stolen-pencil-campaign-targets-academia
- 1unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-cont…
- 1unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-natio…
Related groups 1
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 17 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-cont…
/expres.php -
unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-natio…
tdalpacafarm.com/files/kr/contents/upload.php -
asert.arbornetworks.com/stolen-pencil-campaign-targets-academia
bizsonet.ayar.biz bizsonet.com client-message.com client-screenfonts.com docsdriver.com grsvps.com itservicedesk.org pqexport.com scaurri.com secozco.com sharedriver.pw sharedriver.us tempdomain8899.com world-paper.net zwfaxi.com