Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Ruby Sleet

Also known as: CERIUM

Description

Ruby Sleet is a threat actor linked to North Korea's Ministry of State Security. Cerium has been involved in spear-phishing campaigns, compromising devices, and conducting cyberattacks alongside other North Korean threat actors. They have also targeted companies involved in COVID-19 research and vaccine development.

AI Analysis

· 1 week ago

Executive Summary

Ruby Sleet, also known as CERIUM, is a North Korean state-sponsored threat actor linked to the Ministry of State Security. They have been active since at least mid-2020 and are known for spear-phishing campaigns targeting organizations involved in COVID-19 research and vaccine development. Their operations suggest a high level of sophistication with capabilities consistent with Advanced Persistent Threat (APT) groups.

Goals & Targeting

Ruby Sleet's strategic objectives likely include intelligence gathering, disruption of critical infrastructure, and the compromise of sensitive information related to COVID-19 research and vaccine development. Their targeting profile primarily focuses on healthcare, pharmaceutical, and biotechnology sectors within countries known to have robust pandemic response capabilities. This aligns with broader North Korean cyber espionage goals aimed at challenging international security interests through targeted cyber operations.

Enhanced Description

Ruby Sleet, operating under the alias CERIUM, represents a North Korean state-sponsored cyber threat group linked to the country's Ministry of State Security. This actor has been involved in multiple cyberattacks, including spear-phishing campaigns, system compromises, and malicious activities in collaboration with other North Korean threat actors. Their primary focus has shifted towards targeting entities engaged in COVID-19 research and vaccine development, reflecting a strategic pivot to exploit emerging vulnerabilities and sensitive research environments. Ruby Sleet's operations demonstrate a high level of technical proficiency and operational coordination typical of state-sponsored APT groups.

Key Capabilities

  • Spear-phishing campaigns using malicious email attachments
  • Compromise of devices through malware deployment
  • Collaboration with other North Korean threat actors
  • Targeting COVID-19 research and vaccine development organizations

MITRE ATT&CK Tactics

Email Compromise (EA)
Credential Access (CA)
Reconnaissance (RE)

ATT&CK Techniques

T1566.002
T1078
T1233

Software / Tooling

Custom malware
Phishing tools

Campaigns & Victims

Ruby Sleet has been observed launching campaigns since mid-2020, with a notable focus on compromising entities involved in COVID-19 research. Their operational tempo suggests adaptability to emerging opportunities, particularly in targeting sectors relevant to global health crises. The actor's collaboration with other North Korean groups indicates a shared strategic vision and resource pooling.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Use of COVID-19-related themes in phishing campaigns
  • Malware deployment on compromised systems

Recommended Actions

  • Implementing rigorous email filtering solutions
  • Conducting regular employee training on phishing awareness
  • Monitoring for suspicious activities related to COVID-19 research
  • Enhancing network perimeter defenses and intrusion detection systems

Suggested Tags

APT
cyber_espionage
healthcare_sector
pharmaceutical_sector
COVID-19_research

Confidence Assessment

High confidence in Ruby Sleet's association with North Korea and targeting of COVID-19 research due to corroborated intelligence. Limited visibility into specific tools or infrastructure used by this group remains an information gap.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
Government Targeting
APT
cyber_espionage
healthcare_sector
pharmaceutical_sector
COVID-19_research

Details

Type
Unknown
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.