Threat actor
Moonstone Sleet
Last fetched
Moonstone Sleet is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 104 techniques and also known as 1 other name.
Also known as
Storm-1789
Description
[Moonstone Sleet](https://attack.mitre.org/groups/G1036) is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, [Lazarus Group](https://attack.mitre.org/groups/G0032), but has differentiated its tradecraft since 2023. [Moonstone Sleet](https://attack.mitre.org/groups/G1036) is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.(Citation: Microsoft Moonstone Sleet 2024)
Techniques by tactic
Command and Control
- T1001.003 · Protocol or Service Impersonation
- T1008 · Fallback Channels
- T1071.001 · Web Protocols
- T1090.001 · Internal Proxy
- T1090.002 · External Proxy
- T1102.002 · Bidirectional Communication
- T1104 · Multi-Stage Channels
- T1105 · Ingress Tool Transfer
- T1132.001 · Standard Encoding
- T1571 · Non-Standard Port
- T1573.001 · Symmetric Cryptography
Discovery
- T1010 · Application Window Discovery
- T1012 · Query Registry
- T1016 · System Network Configuration Discovery
- T1033 · System Owner/User Discovery
- T1046 · Network Service Discovery
- T1049 · System Network Connections Discovery
- T1057 · Process Discovery
- T1082 · System Information Discovery
- T1083 · File and Directory Discovery
- T1124 · System Time Discovery
- T1217 · Browser Information Discovery
- T1680 · Local Storage Discovery
Execution
- T1047 · Windows Management Instrumentation
- T1053.005 · Scheduled Task
- T1059.001 · PowerShell
- T1059.003 · Windows Command Shell
- T1059.005 · Visual Basic
- T1106 · Native API
- T1203 · Exploitation for Client Execution
- T1204.002 · Malicious File
- T1569.002 · Service Execution
- T1574.001 · DLL
- T1574.013 · KernelCallbackTable
Stealth
- T1027 · Obfuscated Files or Information
- T1027.007 · Dynamic API Resolution
- T1027.009 · Embedded Payloads
- T1027.013 · Encrypted/Encoded File
- T1036.003 · Rename Legitimate Utilities
- T1036.004 · Masquerade Task or Service
- T1036.005 · Match Legitimate Resource Name or Location
- T1055.001 · Dynamic-link Library Injection
- T1070 · Indicator Removal
- T1070.003 · Clear Command History
- T1070.004 · File Deletion
- T1070.006 · Timestomp
- T1078 · Valid Accounts
- T1134.002 · Create Process with Token
- T1140 · Deobfuscate/Decode Files or Information
- T1202 · Indirect Command Execution
- T1218 · System Binary Proxy Execution
- T1218.005 · Mshta
- T1218.011 · Rundll32
- T1542.003 · Bootkit
- T1564.001 · Hidden Files and Directories
- T1574.001 · DLL
- T1574.013 · KernelCallbackTable
- T1620 · Reflective Code Loading
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to Moonstone Sleet today — this states the absence of a published link, not that Moonstone Sleet has no infrastructure.
References
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Moonstone Sleet into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.