Moonstone Sleet

MITRE ATT&CK: G1036 View on attack.mitre.org

Aliases: Storm-1789, Moonstone Sleet, LABYRINTH CHOLLIMA

First seen
2023-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-22 00:33:10
Profile updated
2026-07-07 12:28:19

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications media-and-entertainment

Context

Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.

Detection coverage

  • 1 YARA rules
  • 520 Sigma rules

Malware & tools used

  • Malware (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Email Accounts (attack-pattern)
  • Email Addresses (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Gather Victim Org Information (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Malicious File (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Virtual Private Server (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Upload Malware (attack-pattern)
  • Phishing for Information (attack-pattern)
  • Compromise Software Supply Chain (attack-pattern)
  • Service Execution (attack-pattern)
  • Domains (attack-pattern)
  • Browser Information Discovery (attack-pattern)
  • Spearphishing via Service (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)

Reports & references

  • raw.githubusercontent.com — Microsoftmapping (report)
  • MITRE ATT&CK — G1036 (report)
  • Microsoft — Moonstone Sleet Emerges As New North Korean Threat Actor With New Bag Of Tricks (report)

External references