Emerald Sleet

2023-04-18 • MicrosoftHow Microsoft names threat actors

Microsoft tracks this actor as Emerald Sleet, the name it adopted in 2023 for the North Korean state group formerly designated THALLIUM, which other researchers describe as overlapping with Kimsuky and Velvet Chollima. The group has remained highly active, primarily conducting espionage against individuals working in international affairs, especially those whose expertise touches Northeast Asia, as well as non-governmental organizations, government agencies, and media worldwide. Its core tradecraft is spear-phishing, including impersonating reputable academic institutions and non-governmental organizations to elicit expert commentary on North Korea-related foreign policy. In early 2025 Microsoft observed a new approach in which the actor poses as a South Korean government official, builds rapport over time, then sends a spear-phishing email with a PDF attachment directing the recipient to run administrator-level PowerShell code; the code installs a browser-based remote-desktop tool and registers the victim's device using a downloaded certificate, giving the actor remote access for data theft. Microsoft has also documented the group using large language models to research North Korea experts, generate phishing content, and study known software vulnerabilities to identify exploitation paths.

Related Actors

Related Reports in This Cluster

Top Authors

View Emerald Sleet reports only

View Emerald Sleet reports only