Ruby Sleet

2023-04-18 • MicrosoftHow Microsoft names threat actors

Ruby Sleet is Microsoft’s designation for a North Korean threat actor that the company has tracked since 2020. Microsoft publicly profiled the group under this name in November 2024, describing increasingly sophisticated phishing and software-compromise operations against aerospace, defense, satellite, and weapons-system targets. The actor researches victims’ environments, develops capabilities tailored to software they use, signs malware with legitimate certificates obtained from compromised organizations, and distributes backdoored virtual-private-network clients, installers, and other trusted applications. In December 2023, Ruby Sleet compromised a South Korean construction company and replaced legitimate VeraPort software with a malicious version that communicated with the group’s infrastructure. Microsoft assesses that theft of aerospace and defense technology could help North Korea improve its understanding of missiles, drones, and related systems, making intelligence collection and technology acquisition central objectives of the activity.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster