Stolen Pencil Trojan
Stolen Pencil, also known as Stolepen, is a trojan that targets devices using Google Chrome on Microsoft Windows. It was first observed in May 2018.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Stolen Pencil, also known as Stolepen, is a trojan that targets devices using Google Chrome on Microsoft Windows. It was first observed in May 2018.
Affected platforms
The following platforms are known to be affected:
Threat details
Stolen Pencil is distributed through a spear phishing campaign that contains a malicious PDF attachment. Once opened, the PDF will prompt the user to install a malicious Chrome extension.
Once installed, Stolen Pencil will log keystrokes and replace Ethereum wallet addresses with the attacker’s own wallet. The malware will also create administrator accounts, enable Remote Desktop Protocol (RDP) on the compromised device, and then add RDP as an exception to firewall rules.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
If Remote Desktop Protocol (RDP) is not used, then ensure port 3389 (TCP/UDP) is blocked at your internet firewall. If RDP is used, then:
|
Last edited: 11 January 2022 9:38 am