Home/Threat Actor/Moonstone Sleet (Storm-1789)
Threat Actor

Moonstone Sleet (Storm-1789)

moonstone_sleet · north_korea · active since 2023-08

Moonstone Sleet (Microsoft canonical naming, formerly Storm-1789) is a DPRK state actor active publicly since at least August 2023 with primary dual operational mission objectives: cyberespionage intelligence collection targeting defense industrial base / drone technology / aircraft parts / software development / IT services / education sectors, AND financial revenue generation for the DPRK regime through custom ransomware + (post-March 2025) Qilin RaaS commodity-ransomware affiliate operations; early operational era extensively reused Diamond Sleet Comebacker malware code before establishing distinct identity per Microsoft May 28, 2024 canonical disclosure; signature tradecraft includes fake-company-establishment (StarGlow Ventures + C.C. Waterfall fake software development / IT services companies impersonating blockchain and AI startups), trojanized PuTTY initial-access via LinkedIn / Telegram / freelancing platforms, malicious npm packages targeting software developers, fully functional DeTankWar / DeFiTankWar tank-themed malicious game delivering YouieLoad custom malware loader, FakePenny custom ransomware with $6.6 million BTC ransom demand (operationally significant escalation from prior DPRK- cluster ransomware demands and FakePenny note closely overlaps with Seashell Blizzard NotPetya note), SplitLoader installer/dropper, hands-on-keyboard operations for high- value compromises, remote-IT-worker employment-seeking operational extension, March 2025 pivot to Qilin RaaS (first DPRK cluster deploying commodity-RaaS-developed ransomware)

fills dual-mission DPRK cluster cell with signature fake-company + malicious-game tradecraft complementing existing 8 DPRK clusters in the curated corpus.

north_korea confidence: high 7 aliases MITRE ATT&CK G1036 ↗

Profile

Moonstone Sleet (canonical Microsoft Threat Intelligence Center naming Moonstone Sleet.

Microsoft prior emerging- cluster naming Storm-1789) is a Democratic People's Republic of Korea (DPRK) state actor active publicly since at least August 2023, with primary dual operational mission objectives: (a) cyberespionage intelligence collection targeting defense industrial base, drone technology, aircraft parts manufacturing, software development, IT services, and education sectors.

(b) financial revenue generation for the DPRK regime through custom ransomware deployment and (post-March 2025) Qilin RaaS commodity- ransomware affiliate operations. The cluster operates within the broader Lazarus Group ecosystem and shares operational tradecraft heritage with Diamond Sleet (Microsoft canonical naming for Lazarus Group / ZINC), early operational era extensively reused Diamond Sleet Comebacker malware code. Per Microsoft, Moonstone Sleet has since "established itself as a distinct, well-resourced North Korean threat actor" with bespoke infrastructure and tradecraft conducting concurrent operations with Diamond Sleet rather than operating as a Diamond Sleet sub-cluster. Operational phases: (1) OPERATIONAL EMERGENCE WITH DIAMOND SLEET OVERLAPS (August 2023). First detected by Microsoft August 2023 with strong Diamond Sleet code-reuse pattern (Comebacker), early trojanized PuTTY initial-access tradecraft via LinkedIn / Telegram / freelancing platforms. (2) MALICIOUS NPM PACKAGES SOFTWARE DEVELOPER TARGETING (2023-2024). Operational extension to malicious npm packages disguised as skills-assessment / project-collaboration engagement targeting software developers via freelancing platforms and LinkedIn. (3) FAKE COMPANY ESTABLISHMENT ERA (January 2024+). Signature tradecraft maturation: StarGlow Ventures fake software development company (January-April 2024 email campaign targeting thousands of education + software development organizations), C.C. Waterfall fake software development / IT services company. Custom domains, fake employee personas, social media accounts add legitimacy. (4) MALICIOUS GAME DISTRIBUTION ERA (February 2024+). DeTankWar / DeFiTankWar / DeTankZone / TankWarsZone fully functional malicious tank-themed game distributed via fake blockchain-company social engineering. YouieLoad custom malware loader delivered via game execution. (5) FAKEPENNY CUSTOM RANSOMWARE DEPLOYMENT (April 2024). $6.6 million BTC ransom demand, operationally significant because this stark contrast to lower ransom demands of previous North Korea ransomware attacks (WannaCry, H0lyGh0st). FakePenny ransom note closely overlaps with Seashell Blizzard NotPetya note. Drone technology + aircraft parts manufacturer compromises concurrent. (6) MICROSOFT CANONICAL DISCLOSURE (May 28, 2024). Comprehensive disclosure operationally established canonical Moonstone Sleet naming graduating from emerging-cluster Storm-1789 designation. (7) QILIN RaaS COMMODITY-RANSOMWARE PIVOT (March 2025). Operational extension to Qilin ransomware-as-a-service deployment, first DPRK-cluster instance of deploying commodity-RaaS-developed ransomware rather than custom. Operationally consistent with broader DPRK cluster ecosystem trend of operational diversification into commodity- cybercrime ecosystems.

Signature operational tradecraft
  • Fake-company-establishment tradecraft: StarGlow Ventures + C.C. Waterfall fake software development / IT services companies impersonating blockchain and AI startup verticals with custom domains, fake employee personas, social media accounts for social engineering legitimacy.
  • Malicious-game-development tradecraft: DeTankWar / DeFiTankWar tank-themed fully functional malicious game delivered as YouieLoad malware loader via fake blockchain- company social engineering. Game requires registration and loads malicious DLLs on launch.
  • FakePenny custom ransomware: $6.6 million BTC ransom demand (operationally significant escalation from prior DPRK-cluster ransomware demands). Loader + encryptor architecture. Ransom note overlaps with Seashell Blizzard NotPetya note (deliberate stylistic borrowing).
  • Trojanized PuTTY initial-access: signature initial- access tradecraft from August 2023 onward via LinkedIn, Telegram, freelancing platforms.
  • Malicious npm packages targeting software developers: disguised as skills-assessment / project-collaboration engagement.
  • YouieLoad custom malware loader: in-memory payload loading + malicious-service creation for network + user discovery and browser data collection.
  • SplitLoader installer/dropper: complementary custom installer tooling.
  • Hands-on-keyboard operations for high-value compromise targets: further discovery + credential theft.
  • Remote-IT-worker employment-seeking operational extension: cluster operations include seeking legitimate software development employment, operationally extending DPRK IT-worker revenue-generation strategic initiative.
  • Qilin RaaS deployment (post-March 2025): pivot to commodity-RaaS-affiliate ransomware operations.
  • Dual revenue + intelligence mission: operationally distinct from competing DPRK clusters with single-mission operational pattern. Fills the dual-mission DPRK cluster cell with signature fake-company-establishment + malicious-game-development tradecraft in the curated corpus, complementing broader DPRK coverage (andariel, apt37_reaper, apt38_bluenoroff, citrine_sleet, contagious_interview, kimsuky, lazarus_group, sapphire_sleet). Operationally distinct through signature fake-company tradecraft (StarGlow Ventures + C.C. Waterfall), signature malicious-game tradecraft (DeTankWar), FakePenny custom ransomware with $6.6M BTC demand, dual revenue + intelligence mission, March 2025 Qilin RaaS pivot.

Aliases

7
moonstone sleetmoonstone-sleetmoonstone_sleetstorm-1789storm1789moonstone_sleet_dprkdprk moonstone sleet

Notable Campaigns

10
2025March 2025 Pivot to Qilin Ransomware-as-a-Service Deployment
2024-PresentRemote IT Worker Employment-Seeking Operational Extension
2024StarGlow Ventures Fake Software Development Company Campaign (January-April 2024)
2024C.C. Waterfall Fake Software Development Company (2024)
2024DeTankWar Malicious Tank-Themed Game Distribution (February 2024)
2024FakePenny Custom Ransomware Deployment ($6.6M BTC Demand, April 2024)
2024Drone Technology + Aircraft Parts Manufacturer Compromises (April-May 2024)
2024Microsoft CYBERWARCON Canonical Moonstone Sleet Disclosure (May 28, 2024)
2023-2024Malicious npm Packages Software Developer Targeting (2023-2024)
2023Moonstone Sleet Operational Emergence (August 2023)

Attribution & Reporting

Attributed by
Microsoft Threat Intelligence CenterMandiantCrowdStrikeSOPHOS X-OpsTrend MicroSymantec / Broadcom Threat Hunter TeamSentinelOne / SentinelLabsRecorded Future Insikt GroupDTEX SystemsVolexityKaspersky GReATUS FBIUS CISAUS Department of the Treasury OFAC
Key reporting
reportMicrosoft Threat Intelligence Center: Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks (May 28, 2024), canonical comprehensive Moonstone Sleet disclosure
reportMicrosoft Threat Intelligence Center: Moonstone Sleet + Qilin RaaS Pivot Disclosure (March 2025)
reportMandiant: DPRK Cluster Tracking, Moonstone Sleet / Storm-1789 Adjacent Activity
reportCrowdStrike Global Threat Report: DPRK Cluster Tracking
reportSOPHOS X-Ops: Moonstone Sleet Operational Profile
reportTrend Micro: DPRK State-Aligned Cluster Tracking
reportSymantec / Broadcom Threat Hunter Team: DPRK Cluster Continued Tracking
reportSentinelLabs: Moonstone Sleet Tooling Analysis (SplitLoader, YouieLoad, FakePenny)
reportRecorded Future Insikt Group: DPRK Cyber Operations Tracking
reportDTEX Systems: DPRK Cyber Attribution Analysis
reportVolexity: DPRK Cluster Operational Profile
reportKaspersky GReAT: DPRK Cluster Tracking
reportUS FBI: DPRK Threat Analyses
reportUS CISA: DPRK Cyber Activity Advisories
reportUS Department of the Treasury OFAC: DPRK Cyber Sanctions
reportMITRE ATT&CK Group G1036, Moonstone Sleet
reportMalpedia Actor Profile: Moonstone Sleet

Operational

State sponsor

Democratic People's Republic of Korea (DPRK) state actor, Microsoft Threat Intelligence Center canonical naming Moonstone Sleet, formerly tracked under emerging-cluster naming Storm-1789. The cluster operates within the broader Lazarus Group ecosystem and shares operational tradecraft heritage with Diamond Sleet (Microsoft canonical naming for Lazarus Group / ZINC), when first detected by Microsoft, Moonstone Sleet "demonstrated strong overlaps with Diamond Sleet, extensively reusing code from known Diamond Sleet malware like Comebacker" (Comebacker was first observed in January 2021 in connection with a Diamond Sleet campaign targeting security researchers). Per Microsoft, "Moonstone Sleet quickly shifted to its own bespoke infrastructure and attacks. Subsequently, Microsoft has observed Moonstone Sleet and Diamond Sleet conducting concurrent operations, with Diamond Sleet still utilizing much of its known, established tradecraft." The cluster has now "established itself as a distinct, well-resourced North Korean threat actor" per Microsoft's May 28, 2024 canonical disclosure. Primary operational mission objectives are dual: (a) cyberespionage intelligence collection targeting defense industrial base, drone technology, aircraft parts manufacturing, software development, IT services, and education sectors.

(b) financial revenue generation for the DPRK regime through custom ransomware deployment. Operationally significant operational distinctness from adjacent DPRK clusters through (a) signature fake-company- establishment tradecraft (StarGlow Ventures, C.C. Waterfall created as fake software development / IT services companies impersonating blockchain and AI startups)

(b) signature malicious-game-development tradecraft (custom tank-themed game DeTankWar / DeFiTankWar / DeTankZone / TankWarsZone delivered as malware loader)

(c) signature FakePenny custom ransomware with significantly higher ransom demands ($6.6 million BTC vs prior DPRK-cluster ransomware demands typically $100,000)

(d) signature ransomware-note overlap with Seashell Blizzard NotPetya note.

(e) signature remote-IT-worker employment-seeking operational extension beyond traditional DPRK IT-worker programs.

(f) March 2025 pivot to deploying Qilin RaaS ransomware (joining Qilin RaaS gang per Microsoft tracking). No formal attribution to a specific DPRK government agency or Reconnaissance General Bureau unit has been publicly asserted by any government cybersecurity authority, Microsoft tracks the cluster as DPRK state-aligned at the broader ecosystem level.

Motivations
cryptocurrency_and_financial_theft, dprk_regime_revenue_generation, cyberespionage_intelligence_collection, defense_industrial_base_intellectual_property_theft, drone_technology_intellectual_property_theft, aircraft_parts_intellectual_property_theft, software_development_industry_targeting, it_services_industry_targeting, dual_revenue_and_intelligence_mission
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)31/60 · 51%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MALICIOUS NPM PACKAGESMETERPRETERSPLITLOADERSTARGLOW VENTURES FAKE COMPANY

CVEs Exploited

3
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin