Onyx Sleet uses array of malware to gather intelligence for North Korea
2024-07-25 • Microsoft •
Microsoft assesses Onyx Sleet as a North Korean threat actor conducting cyber espionage against military, defense, technology, engineering, and energy targets, with primary activity in India, South Korea, and the United States. The actor historically used spear-phishing but more recently shifted toward exploiting N-day vulnerabilities such as TeamCity CVE-2023-42793, Log4j CVE-2021-44228, Apache ActiveMQ CVE-2023-46604, Confluence CVE-2023-22515, and PaperCut CVE-2023-27350 for initial access. Its toolset includes custom RATs and backdoors such as Dtrack, Dora RAT, TigerRAT, SmallTiger, LightHand, and ValidAlpha, alongside off-the-shelf tools including Sliver, RMM tools, SOCKS proxy tools, Ngrok, masscan, Themida, and VMProtect. Microsoft notes that Onyx Sleet often uses leased VPS and compromised cloud infrastructure for C2, relies on custom encryption, obfuscation, and in-memory execution, and has been tied to attacks against aerospace, defense, education, construction, and manufacturing organizations. The reporting links Onyx Sleet to aliases including Andariel, SILENT CHOLLIMA, DarkSeoul, Stonefly, and TDrop2, and highlights its persistence as a DPRK-aligned intelligence and financial threat.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8daa6b20caf4bf384cc7912a73f243c… | 2024-07-25 | 2024-12-13 |
| HASH | fed94f461145681dc9347b382497a72… | 2024-07-25 | 2024-12-13 |
| HASH | 1b88b939e5ec186b2d19aec8f17792d… | 2024-07-25 | 2024-12-13 |
| HASH | f1662bee722a4e25614ed30933b0ced… | 2024-07-25 | 2024-12-13 |
| HASH | 7339cfa5a67f5a4261c18839ef971d7… | 2024-07-25 | 2024-12-13 |
| HASH | 3098e6e7ae23b3b8637677da7bfc0ba… | 2024-07-25 | 2024-12-13 |
| HASH | 29c6044d65af0073424ccc01abcb841… | 2024-07-25 | 2024-12-13 |
| HASH | 0837dd54268c373069fc5c1628c6e3d… | 2023-02-09 | 2024-12-13 |
| HASH | f32f6b229913d68daad937cc72a57aa… | 2021-12-22 | 2024-12-13 |
| HASH | 868a62feff8b46466e9d63b83135a79… | 2021-12-22 | 2024-12-13 |
| HASH | 76cb5d1e6c2b6895428115705d9ac765 | 2024-07-25 | 2024-10-30 |
| HASH | 6624c7b8faac176d1c1cb10b03e7ee5… | 2024-07-25 | 2024-10-30 |
| DOMAIN | advice.uphearth.com | 2024-07-25 | 2024-07-25 |
| DOMAIN | ww3c.bounceme.net | 2024-07-25 | 2024-07-25 |
| IPv4 | 213.139.205.151 | 2024-07-25 | 2024-07-25 |
| IPv4 | 84.38.134.56 | 2024-07-25 | 2024-07-25 |
| IPv4 | 147.78.149.201 | 2024-07-25 | 2024-07-25 |
| IPv4 | 45.155.37.101 | 2024-07-25 | 2024-07-25 |
| IPv4 | 162.19.71.175 | 2023-12-11 | 2024-07-25 |
| IPv4 | 109.248.150.147 | 2023-11-10 | 2024-07-25 |
| DOMAIN | privatemake.bounceme.net | 2023-08-22 | 2024-07-25 |