Also known as: CERIUM
Ruby Sleet is a threat actor linked to North Korea's Ministry of State Security. Cerium has been involved in spear-phishing campaigns, compromising devices, and conducting cyberattacks alongside other North Korean threat actors. They have also targeted companies involved in COVID-19 research and vaccine development.
Executive Summary
Ruby Sleet, also known as CERIUM, is a North Korean state-sponsored threat actor linked to the Ministry of State Security. They have been active since at least mid-2020 and are known for spear-phishing campaigns targeting organizations involved in COVID-19 research and vaccine development. Their operations suggest a high level of sophistication with capabilities consistent with Advanced Persistent Threat (APT) groups.
Goals & Targeting
Ruby Sleet's strategic objectives likely include intelligence gathering, disruption of critical infrastructure, and the compromise of sensitive information related to COVID-19 research and vaccine development. Their targeting profile primarily focuses on healthcare, pharmaceutical, and biotechnology sectors within countries known to have robust pandemic response capabilities. This aligns with broader North Korean cyber espionage goals aimed at challenging international security interests through targeted cyber operations.
Enhanced Description
Ruby Sleet, operating under the alias CERIUM, represents a North Korean state-sponsored cyber threat group linked to the country's Ministry of State Security. This actor has been involved in multiple cyberattacks, including spear-phishing campaigns, system compromises, and malicious activities in collaboration with other North Korean threat actors. Their primary focus has shifted towards targeting entities engaged in COVID-19 research and vaccine development, reflecting a strategic pivot to exploit emerging vulnerabilities and sensitive research environments. Ruby Sleet's operations demonstrate a high level of technical proficiency and operational coordination typical of state-sponsored APT groups.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Ruby Sleet has been observed launching campaigns since mid-2020, with a notable focus on compromising entities involved in COVID-19 research. Their operational tempo suggests adaptability to emerging opportunities, particularly in targeting sectors relevant to global health crises. The actor's collaboration with other North Korean groups indicates a shared strategic vision and resource pooling.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Ruby Sleet's association with North Korea and targeting of COVID-19 research due to corroborated intelligence. Limited visibility into specific tools or infrastructure used by this group remains an information gap.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics