LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1036: Moonstone Sleet

Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.CitationMicrosoft Moonstone Sleet 2024

EnterpriseG1036GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Moonstone Sleet matters because ATT&CK describes a group that combines social engineering infrastructure, fake companies/personas, financially motivated activity, and espionage-oriented operations. For leaders, the practical risk is not one single malware family or platform; it is whether the organization can validate people, files, software sources, and post-compromise behavior before an intrusion becomes credential theft, persistence, command-and-control, or ransomware impact.

Executive priority

Prioritize this as a readiness test across identity, SOC monitoring, incident response, and third-party trust. Executives should ask whether recruiting, vendor, developer, and business-development workflows can spot fake personas and suspicious files; whether SOC coverage includes credential access and persistence behaviors; and whether ransomware resilience covers Windows, Linux, VMware ESXi, and cloud/IaaS systems where relevant to local infrastructure. The ATT&CK relationships make this useful for control prioritization and audit evidence: prove you can detect and respond to phishing, malicious files, software supply chain concerns, LSASS access, scheduled tasks, service execution, registry run keys, web-based C2, tool transfer, and data encryption activity.

Technical view

ATT&CK does not provide a dedicated detection section for Moonstone Sleet, so defenders should validate coverage from the related techniques. Build detections around the chain implied by the relationships: resource development using domains, VPSs, email accounts, and social media accounts; initial access through spearphishing attachments, third-party services, malicious files, and possible software supply chain compromise; execution via user-opened files, services, or scheduled tasks; credential access against LSASS; discovery of users, browsers, systems, and network configuration; persistence through scheduled tasks and run keys; obfuscation, embedded or encoded payloads, and deobfuscation; C2 over web protocols; ingress tool transfer; and encryption for impact. Treat the Qilin relationship as a ransomware-context signal, while avoiding assumptions that every Moonstone Sleet case will use that software.

Likely telemetry

  • Email security and attachment detonation results for spearphishing attachments
  • Logs from collaboration, social, or third-party messaging services used for business communication
  • DNS, proxy, web gateway, and firewall logs for new domains, VPS-hosted infrastructure, HTTP/S or WebSocket-like C2, and tool downloads
  • Endpoint process creation, command-line, parent-child process, and file-write telemetry across monitored operating systems
  • Windows security, Sysmon/EDR, service control manager, scheduled task, and registry autorun telemetry

Detection direction

  • Map existing detections to the related ATT&CK techniques rather than relying on the group name alone.
  • Validate visibility for third-party service phishing; many organizations monitor email better than social media, collaboration, or external messaging workflows.
  • Tune phishing and malicious-file detections for business-context lures, fake companies, and functioning applications or games that may appear legitimate.
  • Baseline and alert on unusual scheduled task creation, service execution, registry run key changes, and suspicious child processes from user-opened files.
  • Harden and monitor for LSASS access attempts, especially when paired with discovery commands or lateral movement preparation.

Mitigation priorities

  • Start with identity and social-engineering controls: phishing-resistant MFA where practical, strong account recovery controls, user reporting paths, and verification procedures for new vendors, recruiters, developers, and business contacts.
  • Reduce malicious-file execution risk with attachment controls, sandboxing, application control, least privilege, and restrictions on untrusted executables/scripts.
  • Strengthen software supply chain governance: verify trusted sources, signed releases, update mechanisms, and change control for software introduced into the environment.
  • Protect credentials by limiting local admin rights, hardening LSASS exposure, and monitoring privileged account use.
  • Reduce persistence opportunities by controlling scheduled task, service, and autorun creation privileges and reviewing deviations from baseline.
Additional notes and limits

This take is based on ATT&CK G1036, its official description, the Microsoft external reference, and the supplied ATT&CK relationships. The most decision-useful feature is the breadth of behaviors: persona/resource development, phishing and malicious files, supply chain concerns, credential access, persistence, C2, tool transfer, obfuscation, and ransomware impact context. Local risk depends on whether the organization’s business processes expose employees to external personas and whether telemetry covers the related platforms and techniques.

MITRE provides no official detection text for this group, and the group object itself lists no platforms or tactics. Platform references here come only from the related software and techniques. This summary does not assert current activity against any specific sector, customer, or environment, and it does not guarantee detection coverage without local telemetry validation.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Moonstone Sleet

Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.CitationMicrosoft Moonstone Sleet 2024

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
63c67cbad2908118...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.