Plutonium
2022-07-14 • Microsoft • Microsoft Digital Defense Report 2022
Microsoft's Threat Intelligence Center tracked PLUTONIUM, subsequently renamed Onyx Sleet under Microsoft's revised naming taxonomy, as a North Korean state-linked threat actor active since at least 2014, associated with clusters also known as DarkSeoul and Andariel, and primarily targeting the energy and defense industries in India, South Korea, and the United States. In a July 2022 report on the H0lyGh0st ransomware operator DEV-0530, Microsoft assessed likely overlap between the two groups: DEV-0530 email accounts were observed communicating with PLUTONIUM attacker accounts, the two operated from shared infrastructure and used custom malware controllers with similar naming conventions, and DEV-0530 was seen using tools created exclusively by PLUTONIUM. Despite these connections, differences in operational tempo, targeting, and tradecraft led Microsoft to assess DEV-0530 and PLUTONIUM as distinct groups, raising the possibility that individuals tied to PLUTONIUM infrastructure were moonlighting on ransomware for personal financial gain rather than acting under state direction.
-
19
Related Actors
-
2
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster