Citrine Sleet
2022-12-06 • Microsoft • Microsoft Digital Defense Report 2023 (MDDR)
Microsoft first tracked this North Korea-nexus activity in December 2022 under the temporary designation DEV-0139, describing an operation in which the actor used cryptocurrency-focused Telegram groups to build trust with employees of a cryptocurrency investment firm before sending a weaponized Excel file that ultimately installed a backdoor; a related sample was distributed via a trojanized MSI installer for a fake application. An October 2023 analysis tied this DEV-0139 activity to the actor Microsoft names Citrine Sleet, consistent with Microsoft's practice of converting temporary DEV designations into named actors once attribution confidence is reached. In August 2024, Microsoft published a profile describing Citrine Sleet as a North Korea-based actor that primarily targets financial institutions and cryptocurrency organizations and individuals for financial gain, using fake trading-platform websites, fabricated job offers, and its AppleJeus trojan; the group also exploited a Chromium zero-day vulnerability to deploy the FudModule rootkit, sharing tooling with the related actor Diamond Sleet. Citrine Sleet is also tracked elsewhere as AppleJeus, Labyrinth Chollima, UNC4736, and Hidden Cobra, and has been attributed to Bureau 121 of North Korea's Reconnaissance General Bureau.
-
60
Related Actors
-
690
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Citrine Sleet reports only