logo

Microsoft: North Korean hackers join Qilin ransomware gang

ID: 06de4364-8e4a-5935-aefb-5d09cdd12dc0

STIX ID: report--06de4364-8e4a-5935-aefb-5d09cdd12dc0

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-03-07

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft observed Moonstone Sleet, a North Korean state-backed threat actor, deploying Qilin ransomware since late February 2025; the group—previously using custom tooling—has shifted to using a RaaS payload and is targeting financial and espionage-related organizations via trojanized software (e.g., PuTTY), custom loaders, malicious packages, fake companies and social engineering, with documented high-impact victims and previous ties to other North Korean ransomware activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.