Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks

2024-05-28 Microsoft

https://www.microsoft.com/en-us/security/blog/2024/05/28/moonstone-sleet-emerges-as-new-north-korean-threat-actor-with-new-bag-of-tricks/

Thumbnail for Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks

Microsoft identifies Moonstone Sleet, formerly Storm-1789, as a distinct North Korean state-aligned actor pursuing financial and espionage objectives. The actor shifted from Diamond Sleet overlaps to its own infrastructure and uses fake companies, job or developer outreach, trojanized PuTTY and npm projects, IT-worker activity, a malicious tank game called DeTankWar/DeFiTankWar, and custom ransomware. The PuTTY chain decrypts staged payloads through SplitLoader, while the npm and game campaigns deliver additional malware or support contact with targets through sites such as detankwar[.]com and defitankzone[.]com. Microsoft says the activity shows a well-resourced DPRK actor combining familiar North Korean tradecraft with bespoke infrastructure and multiple overlapping campaigns.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f59035192098e44b86c4648a0de4078… 2024-05-28 2025-02-16
HASH cb97ec024c04150ad419d1af2d1eb66… 2024-05-28 2024-12-13
HASH 09d152aa2b6261e3b0a1d1c19fa8032… 2024-05-28 2024-12-13
HASH 9863173e0a45318f776e36b1a852938… 2024-05-28 2024-12-13
HASH cafaa7bc3277711509dc0800ed53b82… 2024-05-28 2024-12-13
HASH 39d7407e76080ec5d838c8ebca5182f… 2024-05-28 2024-12-13
DOMAIN ccwaterfall.com 2024-05-28 2024-10-24
HASH ecce739b556f26de07adbfc660a958b… 2024-05-28 2024-05-28
HASH 56554117d96d12bd3504ebef2a8f28e… 2024-05-28 2024-05-28
HASH 70c5b64589277ace59db86d19d846a9… 2024-05-28 2024-05-28
HASH f66122a3e1eaa7dcb7c13838037573d… 2024-05-28 2024-05-28
DOMAIN detankwar.com 2024-05-28 2024-05-28
DOMAIN freenet-zhilly.org 2024-05-28 2024-05-28
DOMAIN defitankzone.com 2024-05-28 2024-05-28
DOMAIN starglowventures.com 2024-05-28 2024-05-28
DOMAIN pointdnt.com 2024-05-28 2024-05-28
DOMAIN bestonlinefilmstudio.org 2024-05-28 2024-05-28
DOMAIN mingeloem.com 2024-05-28 2024-05-28
DOMAIN matrixane.com 2024-04-24 2024-05-28
DOMAIN blockchain-newtech.com 2023-12-08 2024-05-28
DOMAIN chaingrown.com 2023-12-08 2024-05-28

Related Actors

Related Reports

« Back