Threat intelligence
- Suspected origin
- North Korea
- First seen
- 2023-01-01 00:00:00
- Motivation
- Information theft and espionage, Financial gain
- TLP
- WHITE
(Microsoft) Moonstone Sleet is a threat actor behind a cluster of malicious activity that Microsoft assesses is North Korean state-aligned and uses both a combination of many tried-and-true techniques used by other North Korean threat actors and unique attack methodologies. When Microsoft first detected Moonstone Sleet activity, the actor demonstrated strong overlaps with Diamond Sleet (Lazarus Group, Hidden Cobra, Labyrinth Chollima), extensively reusing code from known Diamond Sleet malware like Comebacker and using well-established Diamond Sleet techniques to gain access to organizations, such as using social media to deliver trojanized software. However, Moonstone Sleet quickly shifted to its own bespoke infrastructure and attacks. Subsequently, Microsoft has observed Moonstone Sleet and Diamond Sleet conducting concurrent operations, with Diamond Sleet still utilizing much of its known, established tradecraft.
Moonstone Sleet has an expansive set of operations supporting its financial and cyberespionage objectives. These range from deploying custom ransomware to creating a malicious game, setting up fake companies, and using IT workers.
Also known as
Moonstone SleetStorm-1789Stressed Pungsan
MITRE ATT&CK techniques
T1105 Ingress Tool TransferT1016 System Network Configuration DiscoveryT1033 System Owner/User DiscoveryT1082 System Information DiscoveryT1217 Browser Information DiscoveryT1486 Data Encrypted for ImpactT1591 Gather Victim Org InformationT1598 Phishing for InformationT1587 Develop CapabilitiesT1027 Obfuscated Files or InformationT1140 Deobfuscate/Decode Files or Information
Coverage 1
ransomware
The Gunra ransomware group, linked to state-sponsored actors, is aggressively targeting critical infrastructure and organizations globally, leveraging vulnerabilities in Fortinet and Schneider Electric appliances to gain…
