Home/Threat Actor/Opal Sleet
Threat Actor

Opal Sleet

opal_sleet · north_korea · active since 2017-01

Opal Sleet (Microsoft canonical Sleet taxonomy for DPRK clusters.

previously tracked as OSMIUM under Microsoft's legacy framework) is a North Korean state-sponsored cyber espionage cluster operating under the Reconnaissance General Bureau (RGB) / Bureau 121 DPRK cyber-operations structure with a generalized cyber espionage and intelligence- collection operational mission consistent with broader DPRK state intelligence priorities.

selective targeting of government administration, higher education research, think tanks, financial services institutions, technology vendors, and adjacent organizations primarily in South Korea, United States, Japan, and Western Europe.

spearphishing operational tradecraft with Korean HWP and Microsoft Office macro- enabled lure documents, credential harvesting infrastructure, custom DPRK ecosystem shared tooling (BabyShark, AppleSeed variants), and operational coordination with adjacent DPRK clusters within RGB-controlled ecosystem.

thin public technical documentation relative to higher-profile DPRK clusters, curated for DPRK cyber-operations ecosystem completeness alongside Hazel Sleet and all other DPRK clusters curated separately in this corpus.

north_korea confidence: medium 6 aliases

Profile

Opal Sleet (Microsoft canonical designation, Sleet taxonomy , all DPRK clusters.

previously tracked as OSMIUM under Microsoft's legacy naming framework) is a North Korean state-sponsored cyber espionage cluster operating under the Reconnaissance General Bureau (RGB) / Bureau 121 DPRK cyber-operations structure with a generalized cyber espionage and intelligence-collection operational mission consistent with broader DPRK state intelligence priorities. The cluster's public-record documentation is comparatively thinner than DPRK clusters with high-profile disclosed operations, operationally similar in public-documentation density to Hazel Sleet (hazel_sleet.yaml). Microsoft's threat-actor naming framework recognizes Opal Sleet as an operationally-distinct DPRK cluster based on infrastructure, tradecraft, and persona differentiation, but specific named-operation public disclosures for the cluster remain less dense than for the more publicly-tracked DPRK operations (Lazarus Group, BlueNoroff / Sapphire Sleet, Andariel, Kimsuky, APT37 / Reaper, Moonstone Sleet, Jade Sleet / TraderTraitor, Ruby Sleet, Pearl Sleet, all curated separately). Operational tradecraft includes spearphishing operations with Korean Hangul Word Processor (HWP) and Microsoft Office macro-enabled lure documents for South Korean targeting, credential harvesting infrastructure, custom DPRK ecosystem shared tooling (BabyShark, AppleSeed variants), commodity tools (mimikatz, custom PowerShell stagers), and operational coordination with adjacent DPRK clusters within the broader RGB-controlled ecosystem. The cluster's targeting profile is operationally consistent with broader DPRK state intelligence collection priorities , including selective targeting of government administration organizations, higher education research institutions, think tanks, financial services institutions, technology and software vendors, and adjacent organizations with intelligence-value to the North Korean state. Opal Sleet is curated as a thin-documentation entry relative to flagship DPRK cluster entries in this corpus alongside Hazel Sleet (hazel_sleet.yaml). The entry is structurally significant for DPRK cyber-operations ecosystem completeness rather than for deep technical tradecraft analysis. Analysts requiring technical depth on DPRK cyber-operations should prioritize the higher-public-documentation cluster entries.

Aliases

6
opal_sleetopal sleetosmiumdprk-affiliated-credential-harvesting-clusternorth-korea-affiliated-espionage-cluster-opal-sleetopalsleet

Notable Campaigns

2
2017-2025Microsoft Opal Sleet Operational Tracking (2017-2025)
2017-2025Opal Sleet DPRK Cyber-Operations Ecosystem Coordination Context

Attribution & Reporting

Attributed by
Microsoft Threat Intelligence (MSTIC)Mandiant (Google Threat Intelligence)Recorded Future Insikt GroupKISA (Korea Internet and Security Agency)NIS (Republic of Korea National Intelligence Service)CrowdStrikeSentinelOne
Key reporting
reportMicrosoft Threat Intelligence: DPRK Cyber Threat Actors Overview (including Opal Sleet / OSMIUM)
reportMicrosoft Digital Defense Report (annual editions), DPRK Cyber Operations Coverage
reportMandiant / Google Threat Intelligence: DPRK Cyber Operations Ecosystem
reportRecorded Future Insikt Group: DPRK Cyber Operations Tracking
reportMalpedia Actor Profile: Opal Sleet

Operational

State sponsor

North Korean state-sponsored cyber espionage cluster assessed by Microsoft Threat Intelligence (canonical Opal Sleet designation, Sleet taxonomy assigned to all DPRK- origin clusters in Microsoft's 2023 naming framework; previously tracked as OSMIUM under Microsoft's legacy framework) as operating under North Korean state direction with operational focus on intelligence collection consistent with broader DPRK state intelligence priorities. The cluster has been operationally tracked by Microsoft across multiple years with documented operational tradecraft including spearphishing operations and credential harvesting infrastructure targeting intelligence-value targets in South Korea, the United States, and adjacent geographies. The cluster's public-record documentation is comparatively thinner than DPRK clusters with high-profile disclosed operations (Lazarus Group, BlueNoroff / Sapphire Sleet, Andariel, Kimsuky, APT37 / Reaper, Moonstone Sleet, Jade Sleet / TraderTraitor, Ruby Sleet, Pearl Sleet), operationally similar in public-documentation density to Hazel Sleet (hazel_sleet.yaml).

The cluster is assessed with high confidence to operate under the Reconnaissance General Bureau (RGB) / Bureau 121 DPRK cyber-operations structure or related DPRK intelligence-agency structures. The cluster operates as a North Korean state-sponsored espionage cluster within the broader RGB cyber-operations ecosystem and is operationally distinct from all other DPRK clusters curated separately in this corpus.

Motivations
cyber_espionage, intelligence_collection_for_dprk_strategic_priorities, credential_harvesting_operations, dprk_state_intelligence_priorities, persistent_access_for_long_dwell_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)32/60 · 53%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)1/60 · 1%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MALICIOUS HWP DOCUMENTSMALICIOUS OFFICE MACROS

CVEs Exploited

3
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin