Threat group.View on attack.mitre.org
Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Moonstone Sleet retrieved credentials from LSASS memory. |
| T1016 System Network Configuration Discovery |
Moonstone Sleet has gathered information on victim network configuration. |
| T1027 Obfuscated Files or Information |
Moonstone Sleet delivers encrypted payloads in pieces that are then combined together to form a new portable executable (PE) file during installation. |
| T1027.009 Embedded Payloads |
Moonstone Sleet embedded payloads in trojanized software for follow-on execution. |
| T1027.013 Encrypted/Encoded File |
Moonstone Sleet has used encrypted payloads within files for follow-on execution and defense evasion. |
| T1033 System Owner/User Discovery |
Moonstone Sleet deployed various malware such as YouieLoader that can perform system user discovery actions. |
| T1053.005 Scheduled Task |
Moonstone Sleet used scheduled tasks for program execution during initial access to victim machines. |
| T1071.001 Web Protocols |
Moonstone Sleet used curl to connect to adversary-controlled infrastructure and retrieve additional payloads. |
| T1082 System Information Discovery |
Moonstone Sleet has gathered information on victim systems. |
| T1105 Ingress Tool Transfer |
Moonstone Sleet retrieved a final stage payload from command and control infrastructure during initial installation on victim systems. |
| T1140 Deobfuscate/Decode Files or Information |
Moonstone Sleet delivered payloads using multiple rounds of obfuscation and encoding to evade defenses and analysis. |
| T1195.002 Compromise Software Supply Chain |
Moonstone Sleet has distributed a trojanized version of PuTTY software for initial access to victims. |
| T1204.002 Malicious File |
Moonstone Sleet relied on users interacting with malicious files, such as a trojanized PuTTY installer, for initial execution. |
| T1217 Browser Information Discovery |
Moonstone Sleet deployed malware such as YouieLoader capable of capturing victim system browser information. |
| T1486 Data Encrypted for Impact |
Moonstone Sleet has deployed ransomware in victim environments. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.