logo

Microsoft links North Korean hackers to new FakePenny ransomware

ID: 87ee6082-b1e8-5422-bb10-42e4b70d0a9e

STIX ID: report--87ee6082-b1e8-5422-bb10-42e4b70d0a9e

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-05-28

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

**Moonstone Sleet (Storm-1789)** — Microsoft attributes a North Korean-linked actor, Moonstone Sleet, with expanded tradecraft that includes trojanized applications, social engineering via fake companies, custom loaders, and the recent use of FakePenny ransomware (demanding $6.6M BTC) after prolonged network access; the group targets multiple sectors (software/IT, education, defense) and shows both espionage and financially-motivated activity, indicating evolved capabilities and concurrent operations with other North Korean actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.