Onyx Sleet
2022-07-14 • Microsoft • North Korean threat actor targets small and midsi…
Onyx Sleet is Microsoft’s designation for a North Korean threat actor first observed by the company in 2014. Microsoft publicly profiled the group under this name in July 2024, describing a long-running cyber-espionage mission that later expanded to financial gain. The actor primarily targets military, defense, engineering, energy, technology, construction, education, and manufacturing organizations in India, South Korea, the United States, and elsewhere. Earlier campaigns relied on spear-phishing, while newer operations frequently exploit publicly disclosed vulnerabilities in internet-facing products to deploy loaders, downloaders, custom backdoors, and remote-access trojans. Onyx Sleet maintains an extensive evolving toolset that includes Dtrack, TigerRAT, SmallTiger, LightHand, ValidAlpha, Dora RAT, ransomware, and open-source administration or tunneling utilities. Microsoft also maps the activity to Andariel, Silent Chollima, Stonefly, DarkSeoul, and TDrop2 and notes overlap with other North Korean ransomware infrastructure.
-
19
Related Actors
-
162
Related Reports