Moonstone Sleet & Sin Chong Min

2024-09-16 Pyongyang Papers

https://pyongyangpapers.com/investigations/moonstone-sleet-sin-chong-min/

Thumbnail for Moonstone Sleet & Sin Chong Min

Pyongyang Papers links DPRK IT worker Sin Chong Min to a network of IT workers conducting activity associated with Microsoft’s Moonstone Sleet cluster. The article describes North Korean workers using fake or stolen identities, laptop farms, and remote software development roles to enter legitimate companies, citing the KnowBe4 hiring incident as an example of the risk. It says Moonstone Sleet combined employment-seeking activity with cyber operations and used the fraudulent DeTankWar, also known as DeFiTankWar or DeTankZone, as a copy of DeFiTankLand. The report places Sin Chong Min near the North Korea-China border and argues that DPRK overseas IT work remains a major sanctions evasion and revenue channel alongside cryptocurrency theft.

Related Actors

Related Reports

« Back