There is a new advanced persistent threat (APT) in the global village and it’s called ‘Stolen Pencil’, because it apparently targets academic institutions. “Once gaining a foothold, the threat actors use off-the-shelf tools to ensure persistence, including Microsoft’s Remote Desktop Protocol (RDP) to maintain access. Once gaining a foothold on a user’s system, the threat actors behind STOLEN PENCIL use RDP for remote point-and-click access. Limit RDP access with a firewall to only those systems that require it. Monitor for suspicious RDP connections where there should be none.
Source: The North Africa Journal February 28, 2019 07:29 UTC