Microsoft Threat Intelligence. (2024, May 28). Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks. Retrieved August 26, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupMoonstone Sleet | Moonstone Sleet retrieved credentials from LSASS memory. |
| T1016 System Network Configuration Discovery |
GroupMoonstone Sleet | Moonstone Sleet has gathered information on victim network configuration. |
| T1027 Obfuscated Files or Information |
GroupMoonstone Sleet | Moonstone Sleet delivers encrypted payloads in pieces that are then combined together to form a new portable executable (PE) file during installation. |
| T1027.009 Embedded Payloads |
GroupMoonstone Sleet | Moonstone Sleet embedded payloads in trojanized software for follow-on execution. |
| T1027.013 Encrypted/Encoded File |
GroupMoonstone Sleet | Moonstone Sleet has used encrypted payloads within files for follow-on execution and defense evasion. |
| T1033 System Owner/User Discovery |
GroupMoonstone Sleet | Moonstone Sleet deployed various malware such as YouieLoader that can perform system user discovery actions. |
| T1053.005 Scheduled Task |
GroupMoonstone Sleet | Moonstone Sleet used scheduled tasks for program execution during initial access to victim machines. |
| T1071.001 Web Protocols |
GroupMoonstone Sleet | Moonstone Sleet used curl to connect to adversary-controlled infrastructure and retrieve additional payloads. |
| T1082 System Information Discovery |
GroupMoonstone Sleet | Moonstone Sleet has gathered information on victim systems. |
| T1105 Ingress Tool Transfer |
GroupMoonstone Sleet | Moonstone Sleet retrieved a final stage payload from command and control infrastructure during initial installation on victim systems. |
| T1140 Deobfuscate/Decode Files or Information |
GroupMoonstone Sleet | Moonstone Sleet delivered payloads using multiple rounds of obfuscation and encoding to evade defenses and analysis. |
| T1195.002 Compromise Software Supply Chain |
GroupMoonstone Sleet | Moonstone Sleet has distributed a trojanized version of PuTTY software for initial access to victims. |
| T1204.002 Malicious File |
GroupMoonstone Sleet | Moonstone Sleet relied on users interacting with malicious files, such as a trojanized PuTTY installer, for initial execution. |
| T1217 Browser Information Discovery |
GroupMoonstone Sleet | Moonstone Sleet deployed malware such as YouieLoader capable of capturing victim system browser information. |
| T1486 Data Encrypted for Impact |
GroupMoonstone Sleet | Moonstone Sleet has deployed ransomware in victim environments. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMoonstone Sleet | Moonstone Sleet used registry run keys for process execution during initial victim infection. |
| T1566.001 Spearphishing Attachment |
GroupMoonstone Sleet | Moonstone Sleet delivered various payloads to victims as spearphishing attachments. |
| T1566.003 Spearphishing via Service |
GroupMoonstone Sleet | Moonstone Sleet has used social media services to spear phish victims to deliver trojainized software. |
| T1569.002 Service Execution |
GroupMoonstone Sleet | Moonstone Sleet used intermediate loader malware such as YouieLoader and SplitLoader that create malicious services. |
| T1583.001 Domains |
GroupMoonstone Sleet | Moonstone Sleet registered domains to develop effective personas for fake companies used in phishing activity. |
| T1583.003 Virtual Private Server |
GroupMoonstone Sleet | Moonstone Sleet registered virtual private servers to host payloads for download. |
| T1585.001 Social Media Accounts |
GroupMoonstone Sleet | Moonstone Sleet has created social media accounts to interact with victims. |
| T1585.002 Email Accounts |
GroupMoonstone Sleet | Moonstone Sleet has created email accounts to interact with victims, including for phishing purposes. |
| T1587 Develop Capabilities |
GroupMoonstone Sleet | Moonstone Sleet developed malicious npm packages for delivery to or retrieval by victims. |
| T1587.001 Malware |
GroupMoonstone Sleet | Moonstone Sleet has developed custom malware, including a malware delivery mechanism masquerading as a legitimate game. |
| T1589.002 Email Addresses |
GroupMoonstone Sleet | Moonstone Sleet gathered victim email address information for follow-on phishing activity. |
| T1591 Gather Victim Org Information |
GroupMoonstone Sleet | Moonstone Sleet has gathered information on victim organizations through email and social media interaction. |
| T1598 Phishing for Information |
GroupMoonstone Sleet | Moonstone Sleet has interacted with victims to gather information via email. |
| T1598.003 Spearphishing Link |
GroupMoonstone Sleet | Moonstone Sleet used spearphishing messages containing items such as tracking pixels to determine if users interacted with malicious messages. |
| T1608.001 Upload Malware |
GroupMoonstone Sleet | Moonstone Sleet staged malicious capabilities online for follow-on download by victims or malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.