Moonstone Sleet

2024-05-28 • MicrosoftMoonstone Sleet emerges as new North Korean threa…

Microsoft identified Moonstone Sleet in May 2024 as a new, distinct North Korean state-aligned threat actor, previously tracked under the temporary designation Storm-1789; while it initially overlapped heavily with the actor Diamond Sleet, reusing malware such as Comebacker and similar social-engineering delivery methods, it has since moved to its own dedicated infrastructure and tooling. Moonstone Sleet pursues both espionage and revenue-generation objectives against organizations in the software and information technology, education, and defense-industrial-base sectors. Its tradecraft includes distributing trojanized versions of legitimate software such as PuTTY through platforms like LinkedIn and Telegram; creating fake companies, including ones posing as software-development or IT-consulting firms, to solicit collaboration or job applicants; distributing a malicious blockchain-themed game to deliver a custom malware loader; delivering malware disguised as npm-based technical skills assessments; pursuing employment as remote IT workers at legitimate companies; and, beginning in April 2024, deploying custom ransomware against a previously compromised defense-technology company for financial gain, marking the group's first observed use of ransomware.

Related Actors

Related Reports in This Cluster

Top Authors

View Moonstone Sleet reports only

View Moonstone Sleet reports only