Stolen Pencil
MITRE ATT&CK: G0086 View on attack.mitre.org
Aliases: Velvet Chollima, Black Banshee, Thallium, Operation Stolen Pencil, APT43, Emerald Sleet, THALLIUM, Springtail, Sparkling Pisces, Stolen Pencil
- Origin
- KP
- Actor type
- Espionage
- Last IoC activity
- 2026-07-22 00:38:38
- Profile updated
- 2026-07-07 11:28:33
Context
Stolen Pencil is a threat group likely originating from DPRK that has been active since at least May 2018. The group appears to have targeted academic institutions, but its motives remain unclear.
Detection coverage
- 11 YARA rules
Malware & tools used
- QuasarRAT (malware)
- TinyNuke (malware)
- BabyShark (malware)
- Quasar RAT (malware)
- xRAT (malware)
- Chrome Remote Desktop (malware)
Related threat objects
- Kimsuky (malware)
- TA406 (threat-actor)
- Ruby Sleet (threat-actor)
- Opal Sleet (threat-actor)
- Emerald Sleet (threat-actor)
Reports & references
- bsi.bund.de — Aktive Apt Gruppen Node (report)
- Kaspersky — 57915 (report)
- cfr.org — Kimsuky (report)
- pwc.co.uk — Tracking Kimsuky North Korea Based Cyber Espionage Group Part 2 (report)
- youtu.be — Haskp43Azmm (report)
- bloomberglaw.com — X67Fpndoubv9Vops35A4864Bfiu (report)
- netscout.com — Stolen Pencil Campaign Targets Academia (report)
- Palo Alto Unit 42 — New Babyshark Malware Targets U S National Security Think Tanks (report)
- MITRE ATT&CK — G0086 (report)
- CISA — Aa20 301A (report)
- cybereason.com — Back To The Future Inside The Kimsuky Kgh Spyware Suite (report)
- mandiant.widen.net — Apt43 Report (report)
- asec.ahnlab.com — 57873 (report)
- asec.ahnlab.com — 61082 (report)
- rewterz.com — Rewterz Threat Alert North Korean Apt Kimsuky Aka Black Banshee Active Iocs 29 (report)
- sentinelone.com — A Glimpse Into Future Scarcruft Campaigns Attackers Gather Strategic Intelligence And Target Cybersecurity Professionals (report)
- ctoatncsc.substack.com — Cto At Ncsc Summary Week Ending May 16B (report)
- Broadcom/Symantec — Springtail Kimsuky Backdoor Espionage (report)
- Palo Alto Unit 42 — Kimsuky New Keylogger Backdoor Variant (report)
- asert.arbornetworks.com — Stolen Pencil Campaign Targets Academia (report)
Attributed from
- Emerald Sleet PowerShell User Execution Activity (campaign)
- Kimsuky Remote Desktop Access Activity (campaign)