Moonstone Sleet
MITRE ATT&CK: G1036 View on attack.mitre.org
Aliases: Storm-1789, Moonstone Sleet, LABYRINTH CHOLLIMA
- First seen
- 2023-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-07-22 00:33:10
- Profile updated
- 2026-07-07 12:28:19
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications media-and-entertainment
Context
Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.
Detection coverage
- 1 YARA rules
- 520 Sigma rules
Malware & tools used
- Malware (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Email Accounts (attack-pattern)
- Email Addresses (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Gather Victim Org Information (attack-pattern)
- Scheduled Task (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Malicious File (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Virtual Private Server (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Spearphishing Link (attack-pattern)
- LSASS Memory (attack-pattern)
- Upload Malware (attack-pattern)
- Phishing for Information (attack-pattern)
- Compromise Software Supply Chain (attack-pattern)
- Service Execution (attack-pattern)
- Domains (attack-pattern)
- Browser Information Discovery (attack-pattern)
- Spearphishing via Service (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
Reports & references
- raw.githubusercontent.com — Microsoftmapping (report)
- MITRE ATT&CK — G1036 (report)
- Microsoft — Moonstone Sleet Emerges As New North Korean Threat Actor With New Bag Of Tricks (report)