← Threat Actors / Global / Moonstone Sleet
DOSSIER // MOONSTONE-SLEET

Moonstone Sleet

▲ High Threat
Primary Aliases: APT38 APT45 Citrine Sleet DEV-0139
Confidence Rating 80% (Grounded)

Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.(Citation: Microsoft Moonstone Sleet 2024)

🎯 Target Sectors & Focus

Defense & Aerospace Government & Diplomacy Financial & Crypto Critical Infrastructure
Copied to clipboard

LINK COPIED TO CLIPBOARD