lazarusholic

Everyday is lazarus.dayβ

Analysis of attack activities of Moonstone sleet a division of APT-C-26 (Lazarus) group

2025-02-16, BlueEye
https://blu3eye.gitbook.io/malware-insight/moonstone-sleet-trojaned-putty
#MoonstoneSleet #PuTTY

Contents

Analysis of attack activities of Moonstone sleet a division of APT-C-26 (Lazarus) group
Last updated
Last updated
APT-C-26 (Lazarus) is a highly active advanced persistent group (APT) known for its sophisticated and covert attack methods and techniques. The group has a wide range of activities with goals ranging from cyber espionage for gathering intelligence, custom ransomware attacks for financial gains and causing cyber sabotage. The group is known for a wide range of highly sophsiticated and well-known attacks that have caused massive damage and got a notable recognition. These attacks reflect the huge amount of resources and high technical capabilites the group posses.
In this research I wanna present a case study that I conducted on a new division of the Lazarus group, which was discovered and documented by Microsoft Threat Intelligence Center MSTIC. The group is tracked as Moonstone Sleet (formerly Strom-1789). Moonstone Sleet is a slightly new division of the massive Lazarus …

IoC

f59035192098e44b86c4648a0de4078edbe80352260276f4755d15d354f5fc58
fcb687685f71615c83e9af26087e6036d7dd52a91339ef5c58d3150fd402a586
d65e05c961107c787310c4f369034b096f9484c328b43140d0eb90820c833f9f
63fb47c3b4693409ebadf8a5179141af5cf45a46d1e98e5f763ca0d7d64fb17c
00433ebf3b21c1c055d4ab8a599d3e84f03b328496236b54e56042cef2146b1c