G1036
2024-08-26 • MITRE • Moonstone Sleet
MITRE ATT&CK profiles Moonstone Sleet (G1036) as a North Korea-linked threat actor conducting both financially motivated attacks and espionage operations that previously overlapped significantly with the Lazarus Group before differentiating its tradecraft from 2023 onward. The group is noted for creating fake companies and personas, including social media and email accounts, to engage victim organizations and gather information ahead of intrusions, and for developing unique malware such as a payload delivered through a fully functioning game. Moonstone Sleet has distributed a trojanized version of the PuTTY utility as a software supply chain compromise, developed malicious npm packages, and delivered payloads through spearphishing attachments and social media services. Observed intermediate loaders such as YouieLoader and SplitLoader create malicious services and perform system, network, and browser information discovery, while the group has also dumped credentials from LSASS memory, used scheduled tasks for persistence and execution, and deployed ransomware for impact, reflecting a mixed espionage and financially motivated operational profile.
-
60
Related Actors
-
1
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster