Moonstone Sleet
Aliases: Storm-1789
Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.
Open interactive actor investigation
ATT&CK techniques
T1587.001
MalwareT1033
System Owner/User DiscoveryT1071.001
Web ProtocolsT1585.002
Email AccountsT1589.002
Email AddressesT1140
Deobfuscate/Decode Files or InformationT1591
Gather Victim Org InformationT1053.005
Scheduled TaskT1547.001
Registry Run Keys / Startup FolderT1204.002
Malicious FileT1566.001
Spearphishing AttachmentT1027
Obfuscated Files or InformationT1583.003
Virtual Private ServerT1105
Ingress Tool TransferT1016
System Network Configuration DiscoveryT1598.003
Spearphishing LinkT1003.001
LSASS MemoryT1608.001
Upload MalwareT1598
Phishing for InformationT1195.002
Compromise Software Supply ChainT1569.002
Service ExecutionT1583.001
DomainsT1217
Browser Information DiscoveryT1566.003
Spearphishing via ServiceT1486
Data Encrypted for ImpactT1585.001
Social Media AccountsT1587
Develop CapabilitiesT1082
System Information DiscoveryT1027.013
Encrypted/Encoded FileT1027.009
Embedded Payloads
MalwareT1033
System Owner/User DiscoveryT1071.001
Web ProtocolsT1585.002
Email AccountsT1589.002
Email AddressesT1140
Deobfuscate/Decode Files or InformationT1591
Gather Victim Org InformationT1053.005
Scheduled TaskT1547.001
Registry Run Keys / Startup FolderT1204.002
Malicious FileT1566.001
Spearphishing AttachmentT1027
Obfuscated Files or InformationT1583.003
Virtual Private ServerT1105
Ingress Tool TransferT1016
System Network Configuration DiscoveryT1598.003
Spearphishing LinkT1003.001
LSASS MemoryT1608.001
Upload MalwareT1598
Phishing for InformationT1195.002
Compromise Software Supply ChainT1569.002
Service ExecutionT1583.001
DomainsT1217
Browser Information DiscoveryT1566.003
Spearphishing via ServiceT1486
Data Encrypted for ImpactT1585.001
Social Media AccountsT1587
Develop CapabilitiesT1082
System Information DiscoveryT1027.013
Encrypted/Encoded FileT1027.009
Embedded Payloads