Microsoft links North Korean hackers to new FakePenny ransomware
ID: 87ee6082-b1e8-5422-bb10-42e4b70d0a9e
STIX ID: report--87ee6082-b1e8-5422-bb10-42e4b70d0a9e
Feed Name: Bleeping Computer
**Moonstone Sleet (Storm-1789)** — Microsoft attributes a North Korean-linked actor, Moonstone Sleet, with expanded tradecraft that includes trojanized applications, social engineering via fake companies, custom loaders, and the recent use of FakePenny ransomware (demanding $6.6M BTC) after prolonged network access; the group targets multiple sectors (software/IT, education, defense) and shows both espionage and financially-motivated activity, indicating evolved capabilities and concurrent operations with other North Korean actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
