Also known as: Storm-1789, that combines many tried-, tracked as, North Korea, APT38, Hidden Cobra, the Lazarus Group is, Silent Chollima, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Qilin, DeFiTankWar, DeTankZone, TankWarsZone, OperationTroy, Guardian of Peace, GOP, WHOis Team, Andariel, Subgroup: Andariel, Onyx Sleet, PLUTONIUM
Moonstone Sleet emerged as a distinct unit within the North Korean threat landscape in late 2023, inheriting some operational concepts from its predecessor Lazarus Group while carving out unique methods. The actor maintains dual‑track campaigns: financially motivated ransomware attacks—most recently deploying Qilin ransomware—and elaborate espionage operations that target an extensive array of sectors including government, defense, finance, critical infrastructure, and technology. A hallmark of Moonstone Sleet’s tradecraft is its use of socially engineered fronts such as fake companies and personas. By creating believable business entities and exploiting social media platforms for spearphishing, the group increases click‑through rates and reduces early detection. The actor also produces custom malware disguised as reputable games or legitimate software (e.g., a full game loader), in addition to trojanizing commonly used utilities like PuTTY. Execution strategies frequently involve registry run key persistence, scheduled task creation, and malformed Windows services instantiated by intermediate loaders such as YouieLoader or SplitLoader. The malware also harvests browser data, performs system user discovery, and often employs obfuscated/encoded execution to evade signature‑based defenses. This blend of concealment and legitimate fronting gives the actor a high operational stealth tier. The overall strategy appears to integrate financial reward with intelligence gathering, leveraging compromised hosts for data exfiltration while ensuring the ability to disrupt operations through ransomware if desired.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Moonstone Sleet is a North Korean‑linked threat actor that blends financial exploitation—primarily via Qilin ransomware—with sophisticated espionage and social engineering operations. The group has adopted game‑based malware delivery and forged personas to bypass defenses, leveraging scheduled tasks, registry run keys, and trojanized applications for persistence and initial compromise. Recent activity demonstrates a clear shift away from Lazarus Group tradecraft toward more diversified tactics, increasing both impact and covert data collection.
Goals & Targeting
Moonstone Sleet seeks to maximize value from high‑profile corporate and government targets across the world, focusing on sectors that provide both lucrative financial payoff and sensitive intelligence. By creating sophisticated fake companies, exploiting social media spearphishing vectors, and utilizing embedded game delivery mechanisms, the group reduces discovery risk while widening its attack surface. The dual emphasis on ransomware payout and data exfiltration suggests a long‑term objective of funding state assets through illicit funds coupled with clandestine information gains tailored to North Korean strategic interests.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Moonstone Sleet’s operations exhibit a rapid, multi‑phase attack cadence: an initial spearphishing or social‑media lure delivers a trojanized download or a game loader; once executed the malware establishes persistence through scheduled tasks and registry entries, then pivots to either deploy Qilin ransomware or exfiltrate data. Victims span high‑value targets—including national governments, defense contractors, financial institutions, and critical infrastructure—often in the United States, Europe, East Asia, and the Middle East. The actor’s pattern of leveraging legitimate software fronts reduces detection chances, while its mix of ransomware and espionage indicates strategic patience to adapt tactics as security controls evolve.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in attribution to a North Korean state‑aligned actor based on multiple reputable sources, including Microsoft security blogs and the MISP Galaxy. The documented use of Qilin ransomware, game‑based delivery, and fake company fronts strongly corroborates Moonstone Sleet’s operational footprint. Information gaps remain regarding the actor’s full geographic distribution of attacks, the exact mix between financial and intelligence motives, and the long‑term evolution of its malware ecosystem beyond what has been publicly disclosed. Continuous monitoring and intelligence sharing are essential to refine threat models and maintain detection efficacy.
No campaigns linked yet.
No observed data linked yet.
55
Techniques
57
Tools
0
Campaigns
39
IOCs
0
Observed Data
13
Tactics