Microsoft: North Korean hackers join Qilin ransomware gang
ID: 06de4364-8e4a-5935-aefb-5d09cdd12dc0
STIX ID: report--06de4364-8e4a-5935-aefb-5d09cdd12dc0
Feed Name: Bleeping Computer
Threat Score
Microsoft observed Moonstone Sleet, a North Korean state-backed threat actor, deploying Qilin ransomware since late February 2025; the group—previously using custom tooling—has shifted to using a RaaS payload and is targeting financial and espionage-related organizations via trojanized software (e.g., PuTTY), custom loaders, malicious packages, fake companies and social engineering, with documented high-impact victims and previous ties to other North Korean ransomware activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
