Onyx Sleet uses array of malware to gather intelligence for North Korea

2024-07-25 Microsoft

https://www.microsoft.com/en-us/security/blog/2024/07/25/onyx-sleet-uses-array-of-malware-to-gather-intelligence-for-north-korea/

Thumbnail for Onyx Sleet uses array of malware to gather intelligence for North Korea

Microsoft assesses Onyx Sleet as a North Korean threat actor conducting cyber espionage against military, defense, technology, engineering, and energy targets, with primary activity in India, South Korea, and the United States. The actor historically used spear-phishing but more recently shifted toward exploiting N-day vulnerabilities such as TeamCity CVE-2023-42793, Log4j CVE-2021-44228, Apache ActiveMQ CVE-2023-46604, Confluence CVE-2023-22515, and PaperCut CVE-2023-27350 for initial access. Its toolset includes custom RATs and backdoors such as Dtrack, Dora RAT, TigerRAT, SmallTiger, LightHand, and ValidAlpha, alongside off-the-shelf tools including Sliver, RMM tools, SOCKS proxy tools, Ngrok, masscan, Themida, and VMProtect. Microsoft notes that Onyx Sleet often uses leased VPS and compromised cloud infrastructure for C2, relies on custom encryption, obfuscation, and in-memory execution, and has been tied to attacks against aerospace, defense, education, construction, and manufacturing organizations. The reporting links Onyx Sleet to aliases including Andariel, SILENT CHOLLIMA, DarkSeoul, Stonefly, and TDrop2, and highlights its persistence as a DPRK-aligned intelligence and financial threat.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8daa6b20caf4bf384cc7912a73f243c… 2024-07-25 2024-12-13
HASH fed94f461145681dc9347b382497a72… 2024-07-25 2024-12-13
HASH 1b88b939e5ec186b2d19aec8f17792d… 2024-07-25 2024-12-13
HASH f1662bee722a4e25614ed30933b0ced… 2024-07-25 2024-12-13
HASH 7339cfa5a67f5a4261c18839ef971d7… 2024-07-25 2024-12-13
HASH 3098e6e7ae23b3b8637677da7bfc0ba… 2024-07-25 2024-12-13
HASH 29c6044d65af0073424ccc01abcb841… 2024-07-25 2024-12-13
HASH 0837dd54268c373069fc5c1628c6e3d… 2023-02-09 2024-12-13
HASH f32f6b229913d68daad937cc72a57aa… 2021-12-22 2024-12-13
HASH 868a62feff8b46466e9d63b83135a79… 2021-12-22 2024-12-13
HASH 76cb5d1e6c2b6895428115705d9ac765 2024-07-25 2024-10-30
HASH 6624c7b8faac176d1c1cb10b03e7ee5… 2024-07-25 2024-10-30
DOMAIN advice.uphearth.com 2024-07-25 2024-07-25
DOMAIN ww3c.bounceme.net 2024-07-25 2024-07-25
IPv4 213.139.205.151 2024-07-25 2024-07-25
IPv4 84.38.134.56 2024-07-25 2024-07-25
IPv4 147.78.149.201 2024-07-25 2024-07-25
IPv4 45.155.37.101 2024-07-25 2024-07-25
IPv4 162.19.71.175 2023-12-11 2024-07-25
IPv4 109.248.150.147 2023-11-10 2024-07-25
DOMAIN privatemake.bounceme.net 2023-08-22 2024-07-25

Related Actors

Related Reports

« Back