G1036: Moonstone Sleet
Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.CitationMicrosoft Moonstone Sleet 2024
Security context for executives and security teams
Moonstone Sleet matters because ATT&CK describes a group that combines social engineering infrastructure, fake companies/personas, financially motivated activity, and espionage-oriented operations. For leaders, the practical risk is not one single malware family or platform; it is whether the organization can validate people, files, software sources, and post-compromise behavior before an intrusion becomes credential theft, persistence, command-and-control, or ransomware impact.
Executive priority
Prioritize this as a readiness test across identity, SOC monitoring, incident response, and third-party trust. Executives should ask whether recruiting, vendor, developer, and business-development workflows can spot fake personas and suspicious files; whether SOC coverage includes credential access and persistence behaviors; and whether ransomware resilience covers Windows, Linux, VMware ESXi, and cloud/IaaS systems where relevant to local infrastructure. The ATT&CK relationships make this useful for control prioritization and audit evidence: prove you can detect and respond to phishing, malicious files, software supply chain concerns, LSASS access, scheduled tasks, service execution, registry run keys, web-based C2, tool transfer, and data encryption activity.
Technical view
ATT&CK does not provide a dedicated detection section for Moonstone Sleet, so defenders should validate coverage from the related techniques. Build detections around the chain implied by the relationships: resource development using domains, VPSs, email accounts, and social media accounts; initial access through spearphishing attachments, third-party services, malicious files, and possible software supply chain compromise; execution via user-opened files, services, or scheduled tasks; credential access against LSASS; discovery of users, browsers, systems, and network configuration; persistence through scheduled tasks and run keys; obfuscation, embedded or encoded payloads, and deobfuscation; C2 over web protocols; ingress tool transfer; and encryption for impact. Treat the Qilin relationship as a ransomware-context signal, while avoiding assumptions that every Moonstone Sleet case will use that software.
Likely telemetry
- Email security and attachment detonation results for spearphishing attachments
- Logs from collaboration, social, or third-party messaging services used for business communication
- DNS, proxy, web gateway, and firewall logs for new domains, VPS-hosted infrastructure, HTTP/S or WebSocket-like C2, and tool downloads
- Endpoint process creation, command-line, parent-child process, and file-write telemetry across monitored operating systems
- Windows security, Sysmon/EDR, service control manager, scheduled task, and registry autorun telemetry
Detection direction
- Map existing detections to the related ATT&CK techniques rather than relying on the group name alone.
- Validate visibility for third-party service phishing; many organizations monitor email better than social media, collaboration, or external messaging workflows.
- Tune phishing and malicious-file detections for business-context lures, fake companies, and functioning applications or games that may appear legitimate.
- Baseline and alert on unusual scheduled task creation, service execution, registry run key changes, and suspicious child processes from user-opened files.
- Harden and monitor for LSASS access attempts, especially when paired with discovery commands or lateral movement preparation.
Mitigation priorities
- Start with identity and social-engineering controls: phishing-resistant MFA where practical, strong account recovery controls, user reporting paths, and verification procedures for new vendors, recruiters, developers, and business contacts.
- Reduce malicious-file execution risk with attachment controls, sandboxing, application control, least privilege, and restrictions on untrusted executables/scripts.
- Strengthen software supply chain governance: verify trusted sources, signed releases, update mechanisms, and change control for software introduced into the environment.
- Protect credentials by limiting local admin rights, hardening LSASS exposure, and monitoring privileged account use.
- Reduce persistence opportunities by controlling scheduled task, service, and autorun creation privileges and reviewing deviations from baseline.
Additional notes and limits
This take is based on ATT&CK G1036, its official description, the Microsoft external reference, and the supplied ATT&CK relationships. The most decision-useful feature is the breadth of behaviors: persona/resource development, phishing and malicious files, supply chain concerns, credential access, persistence, C2, tool transfer, obfuscation, and ransomware impact context. Local risk depends on whether the organization’s business processes expose employees to external personas and whether telemetry covers the related platforms and techniques.
MITRE provides no official detection text for this group, and the group object itself lists no platforms or tactics. Platform references here come only from the related software and techniques. This summary does not assert current activity against any specific sector, customer, or environment, and it does not guarantee detection coverage without local telemetry validation.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Moonstone Sleet
Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.CitationMicrosoft Moonstone Sleet 2024
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
