logo

Microsoft Uncovers 'Moonstone Sleet' — New North Korean Hacker Group

ID: 09bff181-4d84-5bea-838a-483efaea70c9

STIX ID: report--09bff181-4d84-5bea-838a-483efaea70c9

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-05-29

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Microsoft attributes a state-aligned North Korean cluster dubbed Moonstone Sleet (tracked as Storm-1789/1877) with campaigns targeting software/IT, education, and defense sectors using social engineering (fake companies, LinkedIn/Telegram freelancing lures), trojanized PuTTY and npm packages, a malicious game loader (YouieLoad/DeTankWar), credential theft from LSASS, and a custom ransomware family (FakePenny) tied to an April 2024 ransom demand; the actor shows overlaps with Lazarus Group tradecraft but operates with distinct infrastructure and evolving tactics that raise supply-chain and developer-targeting concerns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.