Home/Threat Actor/Pearl Sleet
Threat Actor

Pearl Sleet

pearl_sleet · north_korea · active since 2020-01

Pearl Sleet (Microsoft canonical Sleet taxonomy for DPRK clusters) is a North Korean state-sponsored cyber espionage cluster with operationally-distinctive focused mission of intelligence collection against North Korean defectors, diaspora communities, human rights organizations documenting NK violations, journalists covering North Korean affairs, and South Korean civil society organizations supporting defector resettlement.

signature spearphishing tradecraft with Korean Hangul Word Processor (HWP) lure documents, impersonation of journalists/researchers/resettlement officials, KakaoTalk messaging-app social engineering, and credential-harvesting infrastructure mimicking Korean webmail (Naver, Daum) and international webmail (Gmail, ProtonMail)

collected intelligence operationally supports North Korean state priorities of defector intimidation (via family-contact identification), human-rights-documentation countermeasures, and journalist-source-network monitoring; operationally distinct from but ecosystem-adjacent to all other DPRK clusters curated separately (Lazarus, Kimsuky, Andariel, BlueNoroff/Sapphire Sleet, Citrine Sleet, Moonstone Sleet, Jade Sleet, Ruby Sleet, DarkSeoul, Contagious Interview, APT37)

fills the diaspora-and-dissident- intelligence-collection cell in DPRK coverage.

north_korea confidence: medium 6 aliases

Profile

Pearl Sleet (Microsoft canonical designation, Sleet taxonomy , all DPRK clusters) is a North Korean state-sponsored cyber espionage cluster with an operationally-distinctive focused mission of intelligence collection against North Korean defectors, diaspora communities, human rights organizations documenting North Korean human rights violations, journalists and academics covering North Korean affairs, and South Korean civil society organizations supporting defector resettlement and human rights advocacy. The cluster's targeting profile is operationally distinctive within the broader DPRK cyber-operations ecosystem. While other DPRK clusters in this curated corpus operate against foreign governments (Lazarus, Kimsuky), defense contractors (Ruby Sleet, aerospace and defense intelligence), financial institutions and cryptocurrency exchanges (BlueNoroff / Sapphire Sleet, Citrine Sleet, Jade Sleet / TraderTraitor), defense and critical infrastructure (Andariel), or via custom malware and fake-company supply-chain operations (Moonstone Sleet), Pearl Sleet's operational mission is narrowly focused on a victim population (defectors, human rights defenders, NK-coverage journalists, NGOs) that has direct domestic-political significance to the North Korean state. The operational mission alignment is consistent with North Korean state priorities of monitoring, intimidating, and selectively neutralizing diaspora dissent and human rights advocacy that threatens the regime's domestic and international legitimacy. The cluster's signature operational tradecraft is spearphishing with North Korea-themed lure documents and impersonation- based social engineering, including Korean-language Hangul Word Processor (HWP) format lure documents (signature for South Korean targeting given Hangul's dominance in Korean office document workflows), impersonation of South Korean government defector resettlement officials and journalists covering North Korean affairs, KakaoTalk messaging-app social engineering (KakaoTalk dominates the South Korean messaging ecosystem), and credential-harvesting infrastructure mimicking Korean webmail providers (Naver, Daum) and international webmail providers (Gmail, ProtonMail). Custom backdoors observed in cluster operations include broader- DPRK-ecosystem-shared malware families (BabyShark, AppleSeed, FlowerPower PowerShell backdoor) with operational coordination between Pearl Sleet operations and adjacent DPRK cluster operations. The operational mission produces specific intelligence collection objectives including: (1) defector identity and network mapping including family-contact information in North Korea (which creates North Korean state leverage opportunities against the defector via remaining-family threats, a documented North Korean state intimidation pattern)

(2) human rights documentation methodology and source-network intelligence supporting North Korean state countermeasures against international human rights accountability mechanisms.

(3) journalist source-network intelligence including identification of potential defector or insider sources within North Korea.

(4) advance warning of pending publications, documentaries, or human rights reports that might create reputational or political pressure on the North Korean regime. Pearl Sleet is operationally distinct from all other DPRK clusters curated in this corpus, Lazarus Group (lazarus_group.yaml), Kimsuky (kimsuky.yaml), Andariel (andariel.yaml), BlueNoroff / Sapphire Sleet (sapphire_sleet.yaml), Citrine Sleet (citrine_sleet.yaml), Moonstone Sleet (moonstone_sleet.yaml), Jade Sleet / TraderTraitor (jade_sleet_tradertraitor.yaml), Ruby Sleet (ruby_sleet.yaml), DarkSeoul Operators (darkseoul_operators.yaml), Contagious Interview (contagious_interview.yaml), and APT37 / Reaper (apt37_reaper.yaml), though all operate within the broader RGB-controlled DPRK cyber-operations ecosystem sharing some infrastructure and tooling with adjacent clusters. The cluster fills the diaspora-and-dissident-intelligence- collection cell in this curated DPRK coverage.

Aliases

6
pearl_sleetpearl sleetdprk human rights targeting clusternorth korea defector targeting clusterdprk diaspora intelligence collection clusterpearlsleet

Adversary Emulation Plan

4 steps
Runnable Caldera emulation profile Collection - A collection adversary. Ordered along the attack lifecycle; each step maps to an ATT&CK technique with a concrete executor command. For authorized red-team / purple-team exercises only.
0 collection T1005 · Data from Local System darwin
Find company emails
find $(echo ~#{host.user.name}) -type f -size -500k -maxdepth 5 -exec grep -EIr -o "\b[A-Za-z0-9._%+-]+@#{target.org.name}\b" 2>/dev/null {} \;
1 collection T1005 · Data from Local System darwin
Find IP addresses
find $(echo ~#{host.user.name}) -type f -size -500k -maxdepth 5 -exec grep -EIr -o "(($(echo #{domain.broadcast.ip} | cut -d. -f-2))\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)" 2>/dev/null {} \;
2 collection T1005 · Data from Local System darwin, windows, linux
Find files
find /Users -name '*.#{file.sensitive.extension}' -type f -not -path '*/\.*' -size -500k 2>/dev/null | head -5
3 collection T1074.001 · Data Staged: Local Data Staging darwin, linux, windows
Create staging directory
mkdir -p staged && echo $PWD/staged

Notable Campaigns

4
2023-2025Microsoft Pearl Sleet Operational Disclosures (2023-2025)
2020-2025Sustained North Korean Defector Targeting Operations (2020-2025)
2020-2025Human Rights NGO Targeting Pattern
2020-2025Journalist and Media Targeting, North Korea Coverage Beat

Attribution & Reporting

Attributed by
Microsoft Threat Intelligence (MSTIC)Mandiant (Google Threat Intelligence)Recorded Future Insikt GroupCitizen Lab (University of Toronto Munk School)KISA (Korea Internet and Security Agency)NIS (Republic of Korea National Intelligence Service)South Korean Government Defector Resettlement Agency (Hanawon)Stimson Center 38 NorthCommittee for Human Rights in North Korea (HRNK)Open Technology FundSentinelOneESETCrowdStrike
Key reporting
reportMicrosoft Threat Intelligence: DPRK Cyber Threat Actor Pearl Sleet Targets Defectors (2023-2025 disclosures)
reportMicrosoft Digital Defense Report (annual editions), DPRK Cyber Operations Coverage Including Pearl Sleet
reportCitizen Lab: DPRK Defector and Human Rights Organization Targeting
reportRecorded Future: DPRK Human Rights and Defector Targeting Operations
reportDaily NK / NK News: Investigative Reporting on DPRK Targeting of Defectors and Journalists
reportCommittee for Human Rights in North Korea (HRNK): Cyber Targeting Advisories
reportStimson Center 38 North: DPRK Cyber Operations Context
reportMalpedia Actor Profile: Pearl Sleet

Operational

State sponsor

North Korean state-sponsored cyber espionage cluster assessed by Microsoft Threat Intelligence (canonical Pearl Sleet designation, Sleet taxonomy assigned to all DPRK-origin clusters in Microsoft's 2023 naming framework) as operating under North Korean state direction with a focused operational mission of intelligence collection against North Korean defectors, diaspora communities, human rights organizations documenting North Korean human rights violations, journalists and academics covering North Korean affairs, and South Korean civil society organizations supporting North Korean defectors and human rights advocacy. The cluster is assessed with high confidence to operate under the Reconnaissance General Bureau (RGB) / Bureau 121 DPRK cyber-operations structure or under a related DPRK intelligence-agency structure responsible for diaspora-and-dissident intelligence collection. The targeting profile is operationally distinctive within the broader DPRK cyber-operations ecosystem, operating against a victim population (defectors, human rights defenders, NK-coverage journalists, NGOs) that has direct domestic-political significance to the North Korean state rather than the more conventional state-intelligence targeting of foreign governments, defense contractors, or financial-theft victims pursued by other DPRK clusters.

The operational mission alignment is consistent with North Korean state priorities of monitoring, intimidating, and selectively neutralizing diaspora dissent and human rights advocacy that threatens the regime's domestic and international legitimacy. The cluster is operationally distinct from Lazarus Group (lazarus_group.yaml, broader-mandate cluster), Kimsuky (kimsuky.yaml, broader DPRK espionage), Andariel (andariel.yaml, defense and critical infrastructure), BlueNoroff / Sapphire Sleet (sapphire_sleet.yaml, financial theft), Citrine Sleet (citrine_sleet.yaml, cryptocurrency theft), Moonstone Sleet (moonstone_sleet.yaml, custom malware and fake companies), Jade Sleet / TraderTraitor (jade_sleet_tradertraitor.yaml, supply-chain operations), Ruby Sleet (ruby_sleet.yaml, aerospace and defense intelligence), DarkSeoul Operators (darkseoul_operators.yaml), Contagious Interview (contagious_interview.yaml), and APT37 / Reaper (apt37_reaper.yaml), all curated separately in this corpus.

Motivations
cyber_espionage, north_korean_defector_intelligence_collection, human_rights_organization_surveillance, diaspora_community_monitoring, dissident_journalist_surveillance, dprk_regime_domestic_political_security_support, intimidation_and_chilling_effect_on_dissent
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)31/60 · 51%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MALICIOUS DOCX LURESMALICIOUS HWP DOCUMENTSMALICIOUS PDF LURES

CVEs Exploited

3
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin