Skip to content

Microsoft Warns of New North Korean Threat Actor, Moonstone Sleet

Moonstone Sleet's sophisticated tactics include trojanized tools and a new ransomware. Microsoft warns of the evolving North Korean threat.

In the picture there are three people who are promoting the mobile of LG company, in the background...
In the picture there are three people who are promoting the mobile of LG company, in the background there is a logo of LG and some video of the mobile phone.

Microsoft Warns of New North Korean Threat Actor, Moonstone Sleet

Microsoft has identified a new North Korean threat actor, dubbed Moonstone Sleet, which has been active since at least August 2023. The group is known for its sophisticated tactics, including the use of trojanized legitimate tools and a new custom ransomware variant called FakePenny.

Moonstone Sleet has been linked to the creation of fake companies and job opportunities to engage with potential targets. However, investigations into two companies, StarGlow Ventures and C.C. Waterfall, have not found concrete evidence of their connection to the group. The group delivers trojanized versions of legitimate tools, such as PuTTY, to infect targets. They have also developed a malicious mobile tank-themed game for malware distribution. Notably, the ransom note used by their FakePenny ransomware overlaps with that of the NotPetya malware used by Seashell Blizzard. Moonstone Sleet uses a combination of old and new techniques to compromise targets' systems, and they have shifted to their own infrastructure and attacks, distinct from Diamond Sleet.

Moonstone Sleet's activities, including the use of FakePenny ransomware which demands significantly higher ransoms compared to other North Korean ransomware, highlight the evolving threat landscape. Despite investigations, the connection between Moonstone Sleet and companies like StarGlow Ventures and C.C. Waterfall remains unconfirmed. Further research and intelligence sharing are crucial to counter this emerging threat.

Read also:

Latest