Moonstone Sleet
Also tracked as Storm-1789
Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.
- Known attack methods
- 30
- Origin
- North Korea
- Motive
- Espionage, Financial gain
- First seen
- 2023
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques · 3 used
Resource Development
9 techniques · 4 used
Initial Access
11 techniques · 2 used
Execution
20 techniques · 3 used
Persistence
22 techniques · 1 used
Privilege Escalation
13 techniques
Stealth
30 techniques · 2 used
Defense Impairment
18 techniques
Credential Access
17 techniques · 1 used
Discovery
34 techniques · 4 used
Lateral Movement
9 techniques
Collection
17 techniques
Command and Control
18 techniques · 2 used
Exfiltration
9 techniques
Impact
15 techniques · 1 used
Reconnaissance4
Resource development7
Initial access3
Persistence1
Stealth4
Credential access1
Discovery4
Command and control2
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.