Ruby Sleet

Aliases: CERIUM, VELVET CHOLLIMA

First seen
2019-01-01 00:00:00
Origin
KP
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-20 19:40:50
Profile updated
2026-07-07 12:12:54

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications

Targeted regions: country_code:us country_code:gb country_code:kr country_code:de

Context

Ruby Sleet is a threat actor linked to North Korea's Ministry of State Security. Cerium has been involved in spear-phishing campaigns, compromising devices, and conducting cyberattacks alongside other North Korean threat actors. They have also targeted companies involved in COVID-19 research and vaccine development.

Related threat objects

Reports & references

  • Microsoft — Health Care Cyberattacks Covid 19 Paris Peace Forum (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)

External references