logo

Microsoft: 'Moonstone Sleet' APT Melds Espionage, Financial Goals

ID: b116419f-65be-50ec-b5a2-c700dd172121

STIX ID: report--b116419f-65be-50ec-b5a2-c700dd172121

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-05-29

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Microsoft researchers identified 'Moonstone Sleet,' a North Korean threat actor combining espionage and financially motivated cybercrime. The group uses social-engineering lures (fake companies, job offers), trojanized software distributed via social platforms and freelancer sites, malicious npm packages, a functional fake video game (DeTankWar) that drops malicious DLLs loaded by a custom loader (YouieLoad), and custom ransomware (FakePenny). Targets include aerospace, education, and software organizations; Microsoft recommends layered defenses (EDR, network/tamper protections, and threat hunting).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.