Moonstone Sleet
Also tracked as Storm-1789
Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.
- Documented techniques
- 30
- Assessed origin
- North Korea
- Assessed motivation
- Espionage, Financial gain
- First seen
- 2023
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
reconnaissance4
resource development7
initial access3
persistence1
credential access1
discovery4
command and control2
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.