Moonstone Sleet
[Moonstone Sleet](https://attack.mitre.org/groups/G1036) is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, [Lazarus Group](https://attack.mitre.org/groups/G0032), but has differentiated its tradecraft since 2023. [Moonstone Sleet](https://attack.mitre.org/groups/G1036) is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.(Citation: Microsoft Moonstone Sleet 2024)
Properties
- stix_id
- intrusion-set--e6db1e55-b199-4b6b-8633-989345ee45e0
- signal_observed_at
- 2026-09-11T17:55:00+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (30)
Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compro
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They
Adversaries may build capabilities that can be used during targeting. Rather than purchasing, freely downloading, or stealing capabilities, adversarie
Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresse
Adversaries may create email accounts that can be used during targeting. Adversaries can use accounts created with email providers to further their op
Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email
Adversaries may embed payloads within other files to conceal malicious content from defenses. Otherwise seemingly benign files (such as scripts and ex
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file
Adversaries may gather information about the victim's organization that can be used during targeting. Information about an organization may include a
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external ad
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to ope
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of p
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents
Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to tr
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run key
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple w
Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<code>servic
Adversaries may create and cultivate social media accounts that can be used during targeting. Adversaries can create social media accounts that can be
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a sp
Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting. Spearphishing for
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a sp
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through info
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is activel
Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can in
Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service providers that will sell
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with exi
Software & Tools (1)
[Qilin](https://attack.mitre.org/software/S1242) is a ransomware family operated as a ransomware-as-a-service (RaaS) that has been active since at lea
Explore this actor's full graph with Ninja Signal