Microsoft Uncovers 'Moonstone Sleet' — New North Korean Hacker Group
ID: 09bff181-4d84-5bea-838a-483efaea70c9
STIX ID: report--09bff181-4d84-5bea-838a-483efaea70c9
Feed Name: The Hacker News
Microsoft attributes a state-aligned North Korean cluster dubbed Moonstone Sleet (tracked as Storm-1789/1877) with campaigns targeting software/IT, education, and defense sectors using social engineering (fake companies, LinkedIn/Telegram freelancing lures), trojanized PuTTY and npm packages, a malicious game loader (YouieLoad/DeTankWar), credential theft from LSASS, and a custom ransomware family (FakePenny) tied to an April 2024 ransom demand; the actor shows overlaps with Lazarus Group tradecraft but operates with distinct infrastructure and evolving tactics that raise supply-chain and developer-targeting concerns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
