Plutonium

2022-07-14 • MicrosoftMicrosoft Digital Defense Report 2022

Microsoft's Threat Intelligence Center tracked PLUTONIUM, subsequently renamed Onyx Sleet under Microsoft's revised naming taxonomy, as a North Korean state-linked threat actor active since at least 2014, associated with clusters also known as DarkSeoul and Andariel, and primarily targeting the energy and defense industries in India, South Korea, and the United States. In a July 2022 report on the H0lyGh0st ransomware operator DEV-0530, Microsoft assessed likely overlap between the two groups: DEV-0530 email accounts were observed communicating with PLUTONIUM attacker accounts, the two operated from shared infrastructure and used custom malware controllers with similar naming conventions, and DEV-0530 was seen using tools created exclusively by PLUTONIUM. Despite these connections, differences in operational tempo, targeting, and tradecraft led Microsoft to assess DEV-0530 and PLUTONIUM as distinct groups, raising the possibility that individuals tied to PLUTONIUM infrastructure were moonlighting on ransomware for personal financial gain rather than acting under state direction.

Related Actors

First seen: Jul 2017
Last seen: Jun 2026

Related Reports in This Cluster

Top Authors

View Plutonium reports only

View Plutonium reports only