Home/Threat Actor/Ruby Sleet
Threat Actor

Ruby Sleet

ruby_sleet · north_korea · active since 2020-01

Ruby Sleet (formerly Microsoft CERIUM) is a North Korean state-sponsored (RGB / Bureau 121) cyber espionage cluster dedicated to aerospace, defense, and nuclear sector intelligence collection assessed to directly support North Korea's ballistic missile, submarine, and nuclear warhead development programs.

primary targeting of US, South Korean, and European defense contractors, military research institutes, and nuclear research institutions via aerospace-themed spearphishing campaigns and fake job-offer social engineering ("Operation Dream Job" aerospace variant)

initial access via spearphishing attachment (malicious HWP, DOCX, PDF lure documents with defense-contractor branding) and credential- harvesting infrastructure.

cluster is operationally distinct from Lazarus Group, Andariel, Kimsuky, and BlueNoroff but operates within the broader RGB-controlled DPRK cyber- operations ecosystem sharing infrastructure with those clusters.

north_korea confidence: medium 8 aliases MITRE ATT&CK G0082 ↗

Profile

Ruby Sleet (Microsoft canonical designation, Sleet taxonomy, all DPRK clusters.

formerly CERIUM under Microsoft's legacy naming framework) is a North Korean state-sponsored cyber espionage cluster assessed with high confidence to operate under the Reconnaissance General Bureau (RGB) / Bureau 121 DPRK cyber-operations structure, dedicated to aerospace, defense, and nuclear sector intelligence collection in direct support of North Korea's strategic weapons development programs. The cluster's operational mission is the most strategically significant of the DPRK-espionage sub-clusters: intelligence collection from aerospace and defense contractors, military research institutes, nuclear research institutions, and government defense agencies is assessed to directly support North Korea's ballistic missile program (technical specifications, propulsion, guidance, reentry vehicle design), submarine development program (hull design, propulsion, weapons integration), and nuclear warhead miniaturization program, providing North Korean weapons scientists with technical intelligence that would otherwise require years of independent development or hundreds of millions of dollars in conventional acquisition expenditure. The cluster's primary initial-access tradecraft is spearphishing and credential harvesting, targeting aerospace and defense professionals with lure documents and fake job offer campaigns using defense contractor branding (Boeing, Lockheed Martin, Northrop Grumman, Raytheon, Airbus, BAE Systems, NASA, ESA, SpaceX). The aerospace-variant spearphishing pattern overlaps with the broader DPRK-wide "Operation Dream Job" social- engineering campaign pattern (in which multiple DPRK clusters use fake job-offer lures on professional networking platforms to target specific sectors), with the aerospace-and-defense sector being Ruby Sleet's signature targeting vertical. The cluster is analytically distinct from the financially- motivated DPRK clusters (BlueNoroff / Sapphire Sleet for cryptocurrency theft, Jade Sleet / TraderTraitor for crypto-exchange supply-chain operations) and the broader- mandate Lazarus Group, Ruby Sleet is a mission-specific espionage cluster with a focused aerospace-and-defense collection mandate rather than the multi-mission portfolio of the broader Lazarus Group structure. The cluster fills the aerospace-and-defense-intelligence-collection cell in this curated DPRK coverage, complementing Andariel (andariel.yaml, defense and critical infrastructure destructive operations), Sapphire Sleet (sapphire_sleet.yaml , cryptocurrency theft), and Moonstone Sleet (moonstone_sleet.yaml, custom malware and fake companies).

Aliases

8
ruby_sleetruby sleetceriumstardust_chollimadprk-aerospace-collection-clusternorth-korea-defense-espionage-clusterruby_sleet_dprkrubysleet

MITRE ATT&CK aliases

6
Additional names MITRE lists for G0082.
APT38NICKEL GLADSTONEBeagleBoyzBluenoroffSapphire SleetCOPERNICIUM

Adversary Emulation Plan

4 steps
Runnable Caldera emulation profile Collection - A collection adversary. Ordered along the attack lifecycle; each step maps to an ATT&CK technique with a concrete executor command. For authorized red-team / purple-team exercises only.
0 collection T1005 · Data from Local System darwin
Find company emails
find $(echo ~#{host.user.name}) -type f -size -500k -maxdepth 5 -exec grep -EIr -o "\b[A-Za-z0-9._%+-]+@#{target.org.name}\b" 2>/dev/null {} \;
1 collection T1005 · Data from Local System darwin
Find IP addresses
find $(echo ~#{host.user.name}) -type f -size -500k -maxdepth 5 -exec grep -EIr -o "(($(echo #{domain.broadcast.ip} | cut -d. -f-2))\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)" 2>/dev/null {} \;
2 collection T1005 · Data from Local System darwin, windows, linux
Find files
find /Users -name '*.#{file.sensitive.extension}' -type f -not -path '*/\.*' -size -500k 2>/dev/null | head -5
3 collection T1074.001 · Data Staged: Local Data Staging darwin, linux, windows
Create staging directory
mkdir -p staged && echo $PWD/staged

Notable Campaigns

3
2022-2023Operation Dream Job, Aerospace and Defense Lure Variant (2022-2023)
2021-2025Sustained Aerospace, Defense, and Nuclear Sector Espionage (2021-2025)
2020CERIUM (Ruby Sleet Legacy) COVID-19 Healthcare Phishing Campaign (2020)

Attribution & Reporting

Attributed by
Microsoft Threat IntelligenceCrowdStrikeMandiant (Google Threat Intelligence)Recorded Future Insikt GroupCISA (US Cybersecurity and Infrastructure Security Agency)NSA (National Security Agency)FBI (Federal Bureau of Investigation)KISA (Korea Internet and Security Agency)NIS (Republic of Korea National Intelligence Service)Unit 42 (Palo Alto Networks)Secureworks Counter Threat UnitESETSentinelOne
Key reporting
reportMicrosoft Threat Intelligence: Nation-State Threat Actor Reporting, CERIUM / Ruby Sleet (November 2020, multiple subsequent updates)
reportCISA / NSA / FBI Joint Cybersecurity Advisory: DPRK Cyber Espionage, Aerospace and Defense Sector (AA22-108A)
reportKISA / NIS (Republic of Korea): North Korean Cyber Threat Advisory, Defense Sector
reportRecorded Future Insikt Group: DPRK Aerospace and Defense Espionage Tracking
reportMandiant: DPRK Threat Actor Landscape, Ruby Sleet Cluster
reportMalpedia Actor Profile: Ruby Sleet

Operational

State sponsor

North Korean state-sponsored espionage cluster assessed with high confidence to operate under the direction of the Reconnaissance General Bureau (RGB), the North Korean intelligence agency responsible for foreign cyber espionage operations and the broader Lazarus Group / Bureau 121 cyber- operations ecosystem. Microsoft Threat Intelligence tracking (canonical Ruby Sleet designation, Sleet taxonomy assigned to all DPRK-origin clusters in Microsoft's updated 2023 naming framework) and industry-wide attribution consensus assess the cluster as a dedicated aerospace, defense, and nuclear sector intelligence-collection unit operating in direct support of North Korea's strategic weapons programs, with intelligence collection assessed to directly support the DPRK's ballistic missile program, submarine development program, and nuclear warhead miniaturization program. The RGB / Bureau 121 nexus is assessed with high confidence based on infrastructure sharing with other known DPRK clusters, targeting profile alignment with North Korean strategic weapons development priorities, and victim profile (defense contractors, aerospace companies, nuclear research institutes) consistent with DPRK strategic intelligence collection requirements.

The cluster is operationally distinct from Lazarus Group (lazarus_group.yaml), Andariel (andariel.yaml), BlueNoroff / Sapphire Sleet (sapphire_sleet.yaml), Kimsuky (kimsuky.yaml), and Moonstone Sleet (moonstone_sleet.yaml), all curated separately, while sharing the broader RGB-controlled DPRK-cyber-operations ecosystem context.

Motivations
cyber_espionage, aerospace_and_defense_technology_collection, nuclear_weapons_program_intelligence_support, ballistic_missile_program_intelligence_support, submarine_development_intelligence_support, defense_contractor_network_penetration, north_korean_strategic_weapons_development_support
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MALICIOUS HWP DOCUMENTSMALICIOUS OFFICE MACROSMALICIOUS PDF LURESMETASPLOIT

CVEs Exploited

3
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin