Moonstone Sleet

APT / StateG1036
Origin🇰🇵 Coreia do Norte
Techniques (MITRE ATT&CK)30
SourceMITRE ATT&CK
State sponsor: Korea (Democratic People's Republic of)Attribution confidence: 50%Target categories: Government, Private sector
Targeted regions: South Korea · Bangladesh Bank · Sony Pictures Entertainment · United States · Thailand · France · China · Hong Kong · United Kingdom · Guatemala +9
Also known as:APT 38APT-C-26APT38ATK117ATK3AndarielApplewormBeagleBoyzBlack ArtemisBluenoroffBureau 121COPERNICIUMCOVELLITECitrine SleetDEV-0139DEV-1222Dark SeoulDiamond SleetG0032G0082Group 77Hastati GroupHidden CobraLabyrinth ChollimaLazarus groupNICKEL GLADSTONENewRomanic Cyber Army TeamNickel AcademyOperation AppleJeusOperation DarkSeoulOperation GhostSecretOperation TroySapphire SleetStardust ChollimaStorm-1789Subgroup: BluenoroffTA404Unit 121Whois Hacking TeamZINCZinc

Vexday analysis

Moonstone Sleet é um agente de ameaça vinculado à Coreia do Norte que conduz tanto ataques motivados financeiramente quanto operações de espionagem, catalogado no MITRE ATT&CK sob o identificador G1036 com 30 técnicas documentadas. O grupo, também rastreado como Storm-1789, apresentava anteriormente sobreposição significativa com o Lazarus Group, mas passou a diferenciar seu conjunto de técnicas a partir de 2023. É notável pela criação de empresas e personas falsas para interagir com entidades-alvo, além do desenvolvimento de malware exclusivo, incluindo uma variante distribuída por meio de um jogo completamente funcional.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity41
Impact: High
T1195.002T1053.005T1547.001T1003.001T1016ENTRYInitial accessCompromiseSoftware Supply C…EXECExecutionScheduled TaskPERSPersistenceRegistry Run Keys/ Startup FolderCREDCredential accessLSASS MemoryDISCDiscoverySystem NetworkConfiguration Dis…IMPACTImpactData Encrypted forImpact

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 4

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

md5_hashe94148c2688de4f86df961d7ee2e8b18Qilinthreatfox
md5_hash2178e0b2e5c6058b6e39486249292f5fQilinthreatfox
md5_hash4ca3438f72d0ee6fc2c0c572db9fa866Qilinthreatfox
md5_hash687483f9b58e995b87af9ab3590333edQilinthreatfox

Moonstone Sleet uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →