ATT&CKGroupsMoonstone Sleet

Moonstone Sleet

G1036

Threat group.View on attack.mitre.org

About this group

Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.

Techniques used30

Procedure examples30

TechniqueProcedure example
T1003.001
LSASS Memory

Moonstone Sleet retrieved credentials from LSASS memory.

T1016
System Network Configuration Discovery

Moonstone Sleet has gathered information on victim network configuration.

T1027
Obfuscated Files or Information

Moonstone Sleet delivers encrypted payloads in pieces that are then combined together to form a new portable executable (PE) file during installation.

T1027.009
Embedded Payloads

Moonstone Sleet embedded payloads in trojanized software for follow-on execution.

T1027.013
Encrypted/Encoded File

Moonstone Sleet has used encrypted payloads within files for follow-on execution and defense evasion.

T1033
System Owner/User Discovery

Moonstone Sleet deployed various malware such as YouieLoader that can perform system user discovery actions.

T1053.005
Scheduled Task

Moonstone Sleet used scheduled tasks for program execution during initial access to victim machines.

T1071.001
Web Protocols

Moonstone Sleet used curl to connect to adversary-controlled infrastructure and retrieve additional payloads.

T1082
System Information Discovery

Moonstone Sleet has gathered information on victim systems.

T1105
Ingress Tool Transfer

Moonstone Sleet retrieved a final stage payload from command and control infrastructure during initial installation on victim systems.

T1140
Deobfuscate/Decode Files or Information

Moonstone Sleet delivered payloads using multiple rounds of obfuscation and encoding to evade defenses and analysis.

T1195.002
Compromise Software Supply Chain

Moonstone Sleet has distributed a trojanized version of PuTTY software for initial access to victims.

T1204.002
Malicious File

Moonstone Sleet relied on users interacting with malicious files, such as a trojanized PuTTY installer, for initial execution.

T1217
Browser Information Discovery

Moonstone Sleet deployed malware such as YouieLoader capable of capturing victim system browser information.

T1486
Data Encrypted for Impact

Moonstone Sleet has deployed ransomware in victim environments.

View all 30 procedure examples

Software1

Campaigns0

None recorded.

References1

  1. Microsoft Moonstone Sleet 2024 Open source
    Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.