← All actors Recent activity

Stolen Pencil G0086

STOLENPENCIL · babyshark · kimjongrat

Indicators
17
Source reports
3
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02
20182019

Overview 17 indicators

Stolen Pencil is a threat group likely originating from DPRK that has been active since at least May 2018. The group appears to have targeted academic institutions, but its motives remain unclear.

domain15G0086-domain.txt
url1G0086.json
url_path1G0086.json

Principal sources 3 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

Timeline 17 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. 1 url_path7 yrs ago

    unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-cont…

    /expres.php

  2. 1 url7 yrs ago

    unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-natio…

    tdalpacafarm.com/files/kr/contents/upload.php

  3. 15 domain8 yrs ago

    asert.arbornetworks.com/stolen-pencil-campaign-targets-academia

    bizsonet.ayar.biz
    bizsonet.com
    client-message.com
    client-screenfonts.com
    docsdriver.com
    grsvps.com
    itservicedesk.org
    pqexport.com
    scaurri.com
    secozco.com
    sharedriver.pw
    sharedriver.us
    tempdomain8899.com
    world-paper.net
    zwfaxi.com

Further reading 4