logo

Onyx Sleet uses array of malware to gather intelligence for North Korea

ID: 29bb215c-4783-53c3-8371-5f23db904ec9

STIX ID: report--29bb215c-4783-53c3-8371-5f23db904ec9

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2024-07-25

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence attributes sustained espionage and some financially-motivated operations to Onyx Sleet (North Korean-linked), documenting its evolution from spear-phishing to exploiting N-day vulnerabilities, use of custom RATs and ransomware (TigerRAT, SmallTiger, LightHand, ValidAlpha), observed campaigns targeting defense, energy, and technology sectors (notably in India, South Korea, and the U.S.), published IOCs (IPs, domains, SHA-256 hashes, fake Tableau certificate), and recommended mitigations and detection queries for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.