Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks
2024-05-28 • Microsoft •
Microsoft identifies Moonstone Sleet, formerly Storm-1789, as a distinct North Korean state-aligned actor pursuing financial and espionage objectives. The actor shifted from Diamond Sleet overlaps to its own infrastructure and uses fake companies, job or developer outreach, trojanized PuTTY and npm projects, IT-worker activity, a malicious tank game called DeTankWar/DeFiTankWar, and custom ransomware. The PuTTY chain decrypts staged payloads through SplitLoader, while the npm and game campaigns deliver additional malware or support contact with targets through sites such as detankwar[.]com and defitankzone[.]com. Microsoft says the activity shows a well-resourced DPRK actor combining familiar North Korean tradecraft with bespoke infrastructure and multiple overlapping campaigns.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f59035192098e44b86c4648a0de4078… | 2024-05-28 | 2025-02-16 |
| HASH | cb97ec024c04150ad419d1af2d1eb66… | 2024-05-28 | 2024-12-13 |
| HASH | 09d152aa2b6261e3b0a1d1c19fa8032… | 2024-05-28 | 2024-12-13 |
| HASH | 9863173e0a45318f776e36b1a852938… | 2024-05-28 | 2024-12-13 |
| HASH | cafaa7bc3277711509dc0800ed53b82… | 2024-05-28 | 2024-12-13 |
| HASH | 39d7407e76080ec5d838c8ebca5182f… | 2024-05-28 | 2024-12-13 |
| DOMAIN | ccwaterfall.com | 2024-05-28 | 2024-10-24 |
| HASH | ecce739b556f26de07adbfc660a958b… | 2024-05-28 | 2024-05-28 |
| HASH | 56554117d96d12bd3504ebef2a8f28e… | 2024-05-28 | 2024-05-28 |
| HASH | 70c5b64589277ace59db86d19d846a9… | 2024-05-28 | 2024-05-28 |
| HASH | f66122a3e1eaa7dcb7c13838037573d… | 2024-05-28 | 2024-05-28 |
| DOMAIN | detankwar.com | 2024-05-28 | 2024-05-28 |
| DOMAIN | freenet-zhilly.org | 2024-05-28 | 2024-05-28 |
| DOMAIN | defitankzone.com | 2024-05-28 | 2024-05-28 |
| DOMAIN | starglowventures.com | 2024-05-28 | 2024-05-28 |
| DOMAIN | pointdnt.com | 2024-05-28 | 2024-05-28 |
| DOMAIN | bestonlinefilmstudio.org | 2024-05-28 | 2024-05-28 |
| DOMAIN | mingeloem.com | 2024-05-28 | 2024-05-28 |
| DOMAIN | matrixane.com | 2024-04-24 | 2024-05-28 |
| DOMAIN | blockchain-newtech.com | 2023-12-08 | 2024-05-28 |
| DOMAIN | chaingrown.com | 2023-12-08 | 2024-05-28 |