Moonstone Sleet

Threat Actor updated 3 months ago (2024-11-29T14:45:24.627Z)
Download STIX
Preview STIX
Moonstone Sleet, a state-sponsored threat actor originating from North Korea, has emerged as a significant cybersecurity concern. The group is involved in the publication of malicious npm and other code packages to popular developer repositories, a tactic that's becoming an increasingly common security epidemic. By poisoning code across the software supply chain, Moonstone Sleet and similar threat actors are able to achieve broad attack surfaces with minimal effort. This method allows them to infiltrate systems undetected, leaving what appears to be harmless software behind while executing remote payloads. Microsoft publicly recognized Moonstone Sleet's activities on May 28, 2024, in a blog post titled "Moonstone Sleet emerges as new North Korean threat actor with new bag of tricks," partially revealing their findings about the group's tactics. Other notable threat actors identified by Microsoft include Peach Sandstorm, Mint Sandstorm, Mabna Institute, Emerald Sleet, and the developing Storm-1877. These entities, like Moonstone Sleet, pose significant threats to digital security worldwide due to their sophisticated and evolving methods of attack. The most recent activity linked to Moonstone Sleet was the publication of a package called "sass-notification" on August 27, 2024. This package uses obfuscated JavaScript to run scripts that download, decrypt, and execute remote payloads, subsequently removing traces of malicious activity. The widespread distribution and stealthy nature of these attacks underscore the critical need for heightened vigilance and robust cybersecurity measures across all sectors.
Description last updated: 2024-10-23T13:02:06.800Z
What's your take? (Question 1 of 0)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Moonstone Sleet Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more