NEW: Group Profiler — instant APT intel lookup. Try it →

Moonstone Sleet

G1036 North Korea EspionageSabotage MITRE ATT&CK →

Also known as: Storm-1789

Overview

Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.

Naming & attribution

Moonstone Sleet is tracked under 2 names across the industry. It uses 30 documented ATT&CK techniques — more than 66% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Storm-1789Microsoft Threat Intelligence

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1027.009 Embedded Payloads — used by 3 of 174 groups
  • T1587 Develop Capabilities — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • CURIUM Iran — 9 shared techniques (23% overlap)
  • Windshift — 9 shared techniques (23% overlap)
  • EXOTIC LILY — 8 shared techniques (22% overlap)
  • Sandworm Team Russia — 19 shared techniques (21% overlap)
  • APT19 China — 9 shared techniques (21% overlap)
  • BITTER — 8 shared techniques (21% overlap)

Malware families with current indicators

One family attributed to Moonstone Sleet, carrying 138 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Qilin 138 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Government · Private sector

Regions

Australia · Bangladesh · Bangladesh Bank · Brazil · Canada · China · Cryptocurrency exchanges in South Korea · France · Germany · Guatemala · Hong Kong · India · Japan · Sony Pictures Entertainment · South Korea · Thailand · United Kingdom · United States

Capabilities

  • Supply-chain compromise — ATT&CK T1195.002

TTPs — 30 techniques across 10 tactics

Tools & malware (1)

Qilin

Reporting (1)