Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Moonstone Sleet

Also known as: Storm-1789, that combines many tried-, tracked as, North Korea, APT38, Hidden Cobra, the Lazarus Group is, Silent Chollima, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Qilin, DeFiTankWar, DeTankZone, TankWarsZone, OperationTroy, Guardian of Peace, GOP, WHOis Team, Andariel, Subgroup: Andariel, Onyx Sleet, PLUTONIUM

Description

Moonstone Sleet emerged as a distinct unit within the North Korean threat landscape in late 2023, inheriting some operational concepts from its predecessor Lazarus Group while carving out unique methods. The actor maintains dual‑track campaigns: financially motivated ransomware attacks—most recently deploying Qilin ransomware—and elaborate espionage operations that target an extensive array of sectors including government, defense, finance, critical infrastructure, and technology. A hallmark of Moonstone Sleet’s tradecraft is its use of socially engineered fronts such as fake companies and personas. By creating believable business entities and exploiting social media platforms for spearphishing, the group increases click‑through rates and reduces early detection. The actor also produces custom malware disguised as reputable games or legitimate software (e.g., a full game loader), in addition to trojanizing commonly used utilities like PuTTY. Execution strategies frequently involve registry run key persistence, scheduled task creation, and malformed Windows services instantiated by intermediate loaders such as YouieLoader or SplitLoader. The malware also harvests browser data, performs system user discovery, and often employs obfuscated/encoded execution to evade signature‑based defenses. This blend of concealment and legitimate fronting gives the actor a high operational stealth tier. The overall strategy appears to integrate financial reward with intelligence gathering, leveraging compromised hosts for data exfiltration while ensuring the ability to disrupt operations through ransomware if desired.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Manufacturing
Telecommunications
Healthcare
Education
Media
Non profit
Critical infrastructure
Transportation
Energy
Aerospace
Information technology
Pharmaceutical
Aviation
Hospitality
Mining
Think tank
Retail
Construction
Chemical
Gaming
Legal services
Oil gas
Maritime
Nuclear
Entertainment
Utilities

Targeted Countries / Regions

US
CN
RU
IL
KP
IR
GB
JP
AE
VN
AU
SA
TW
IN
PK
DE
UA
KR
CA
SG
IT
BY
TR
FR
MX
ES
PL
RO
NG
LB
AZ
KZ
BR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 18 hours ago

Executive Summary

Moonstone Sleet is a North Korean‑linked threat actor that blends financial exploitation—primarily via Qilin ransomware—with sophisticated espionage and social engineering operations. The group has adopted game‑based malware delivery and forged personas to bypass defenses, leveraging scheduled tasks, registry run keys, and trojanized applications for persistence and initial compromise. Recent activity demonstrates a clear shift away from Lazarus Group tradecraft toward more diversified tactics, increasing both impact and covert data collection.

Goals & Targeting

Moonstone Sleet seeks to maximize value from high‑profile corporate and government targets across the world, focusing on sectors that provide both lucrative financial payoff and sensitive intelligence. By creating sophisticated fake companies, exploiting social media spearphishing vectors, and utilizing embedded game delivery mechanisms, the group reduces discovery risk while widening its attack surface. The dual emphasis on ransomware payout and data exfiltration suggests a long‑term objective of funding state assets through illicit funds coupled with clandestine information gains tailored to North Korean strategic interests.

Enhanced Description

Key Capabilities

  • Obfuscated and encoded payload delivery
  • Deployment of Qilin ransomware for financial exploitation
  • Espionage operations across government, finance, defense, critical infrastructure sectors
  • Social engineering using fake companies and personas
  • Game‑based malware delivery via a legitimate gaming application
  • Spearphishing through social media platforms
  • Registry run key persistence
  • Scheduled task execution for initial access and persistence
  • Trojanized PuTTY distribution
  • Malicious npm package exploitation
  • Intermediate loader malware (e.g., YouieLoader, SplitLoader) creating malicious services
  • Browser information collection via loaders

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Reconnaissance
Discovery
Credential Access
Collection
Exfiltration
Impact

ATT&CK Techniques

T1003
T1003.001
T1016
T1033
T1050
T1053
T1053.005
T1055
T1060
T1071
T1071.001
T1078
T1082
T1091
T1105
T1129
T1140
T1204
T1204.002
T1195
T1195.002
T1189
T1583
T1583.001
T1583.003
T1585
T1585.001
T1585.002
T1587
T1587.001
T1589
T1589.002
T1591
T1598
T1598.003
T1608
T1608.001
T1566
T1566.001
T1566.002
T1566.003
T1567.002
T1547
T1547.001
T1555.003
T1059
T1059.001

Software / Tooling

Qilin ransomware
YouieLoader
SplitLoader
Trojanized PuTTY
Malicious npm packages
Custom game-based malware loader
Comebacker

Campaigns & Victims

Moonstone Sleet’s operations exhibit a rapid, multi‑phase attack cadence: an initial spearphishing or social‑media lure delivers a trojanized download or a game loader; once executed the malware establishes persistence through scheduled tasks and registry entries, then pivots to either deploy Qilin ransomware or exfiltrate data. Victims span high‑value targets—including national governments, defense contractors, financial institutions, and critical infrastructure—often in the United States, Europe, East Asia, and the Middle East. The actor’s pattern of leveraging legitimate software fronts reduces detection chances, while its mix of ransomware and espionage indicates strategic patience to adapt tactics as security controls evolve.

IOC Patterns

  • Use of obfuscated or encoded payloads to evade detection
  • Creation and use of fake company identities and personas for social engineering
  • Distribution of malicious code disguised as a legitimate game
  • Domain registrations used for fake companies and personas
  • Email addresses harvested from victims
  • Insertion of tracking pixels in spearphishing emails
  • Registry Run Key entries created by malware
  • Scheduled task names used for execution
  • Creation of malicious Windows services

Recommended Actions

  • Implement detection for obfuscated payloads and encrypted files at the file‑level and network traffic
  • Block known Qilin ransomware signatures, hashes, domain indicators, and C2 endpoints in all security devices
  • Verify authenticity of third–party software—especially games—before deployment; use vendor signing validation
  • Monitor anomalies in financial transaction logs that may indicate ransomware activity or lateral movement
  • Subscribe to threat intelligence feeds focused on North Korean actors for up‑to‑date IOCs
  • Deploy robust email authentication (SPF, DKIM, DMARC) and monitoring to detect social‑media spearphishing attempts
  • Apply application whitelisting or anti‑malware controls to block trojanized applications such as fake PuTTY
  • Set alerts for suspicious registry run key modifications and new scheduled tasks on endpoints
  • Implement domain reputation filtering to block malicious domains used for C2 or fake personas
  • Enforce least privilege and restrict unauthorized Windows service creation

Suggested Tags

North Korea
Moonstone Sleet
Storm-1789
Qilin ransomware
Ransomware
Espionage
Obfuscation
Game-based malware
Lazarus Group Relation
Spearphishing Attachment
Spearphishing SocialMedia
Trojanized Applications
Fake Persona Phishing
Malware via Game
Registry Hijack
Scheduled Task
Malicious NPM

Confidence Assessment

High confidence in attribution to a North Korean state‑aligned actor based on multiple reputable sources, including Microsoft security blogs and the MISP Galaxy. The documented use of Qilin ransomware, game‑based delivery, and fake company fronts strongly corroborates Moonstone Sleet’s operational footprint. Information gaps remain regarding the actor’s full geographic distribution of attacks, the exact mix between financial and intelligence motives, and the long‑term evolution of its malware ecosystem beyond what has been publicly disclosed. Continuous monitoring and intelligence sharing are essential to refine threat models and maintain detection efficacy.

ATT&CK Techniques

Resource Development
10 techniques
Stealth
6 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 7 SHA-256 Hash 5 Domain 8

References

  1. Microsoft Moonstone Sleet 2024 — Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.
  2. attack.mitre.org — Cited by web research for: Sandworm Team
  3. www.trendmicro.com — Cited by web research for: Qilin
  4. attack.mitre.org — Cited by web research for: T1071
  5. www.dragos.com — Cited by web research for: Anubis
  6. learn.microsoft.com — Cited by web research for: Tsunami
  7. apt.etda.or.th — Cited by web research for: Custom ransomware
  8. https://misp-galaxy.org/microsoft-activity-group/ — Cited by AI analysis.
  9. https://fieldeffect.com/blog/moonstone-sleet-shifts-tactics-deploys-qilin-ransomware — Cited by AI analysis.
  10. https://brandefense.io/blog/top-5-ransomware-groups-q2-2026/ — Cited by AI analysis.
  11. https://www.microsoft.com/en-us/security/blog/2004/05/28/moonstone-sleet-emerges-as-new-north-korean-the — Cited by AI analysis.
  12. https://malpedia.caad.fkie.fraunhofer.de/actor/lazarus_group — Cited by AI analysis.

Intel Summary

55

Techniques

57

Tools

0

Campaigns

39

IOCs

0

Observed Data

13

Tactics

Tags

Financial Crimes
Espionage
North Korea
Malware Distribution
Social Engineering
Moonstone Sleet
Storm-1789
Qilin ransomware
Ransomware
Obfuscation
Game-based malware
Lazarus Group Relation
Spearphishing Attachment
Spearphishing SocialMedia
Trojanized Applications
Fake Persona Phishing
Malware via Game
Registry Hijack
Scheduled Task
Malicious NPM

Details

MITRE ID
G1036
Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--e6db1e55-b199-4b6b-8633-989345ee45e0
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.