News Room
16
Share
Operation Moonstone Sleet: North Korean APT Group Deploys New Malware in Global Espionage Campaign
criticalState Cyber Warfare

Operation Moonstone Sleet: North Korean APT Group Deploys New Malware in Global Espionage Campaign

Microsoft identifies Moonstone Sleet, a DPRK actor targeting aerospace and defense sectors with LandUpdate7 malware. This group blends sophisticated espionage with financial ransomware operations.

01 August 2026Last updated 20 August 20265 min readMicrosoft MSTIC
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
State Cyber Warfare
Severity:
Critical
Actor Type:
APT
Geography:
North America
Confidence:
High Confidence
Source:
Microsoft MSTIC
Read Time:
5 min

Executive Summary

Over the past 48 hours, intelligence reports from Microsoft Threat Intelligence (MSTIC) and Mandiant have converged on a significant escalation in activities attributed to a newly identified North Korean state-sponsored actor, designated as Moonstone Sleet. This group, previously tracked under various developmental labels, has transitioned from initial reconnaissance to full-scale operations targeting the aerospace, defense, and high-tech sectors in North America and Europe. The campaign is notable for its hybrid nature, blending traditional espionage with financially motivated ransomware attacks, marking a shift in how Pyongyang-aligned actors resource their operations.

Threat Analysis

Moonstone Sleet employs a sophisticated multi-stage infection vector. Unlike traditional APTs that rely solely on phishing emails, this group has been observed creating entire fake personas and legitimate-looking front companies on professional networking sites. They engage targets with job offers or business opportunities, eventually delivering malicious payloads through trojanized software. Their operations demonstrate a high degree of patience and technical proficiency, often lurking within networks for months before executing their final objective. The actor focuses on high-value intellectual property related to aeronautics and satellite technology, likely to support national strategic requirements.

Technical Details

The group's primary toolkit involves two new malware families: LandUpdate7 and 2Key. Initial access is often gained via a trojanized Tank Game application or malicious PDF readers. Once inside the environment, the actor deploys custom-built loaders that bypass standard EDR signatures by utilizing legitimate system processes for injection. Technical analysis of the LandUpdate7 variant reveals a modular architecture designed to exfiltrate system metadata, browser credentials, and internal documentation. In several instances, Moonstone Sleet has deployed a custom ransomware variant, dubbed FakePenny, as a diversion or a means to fund ongoing operations. This ransomware is uniquely crafted for each target, making signature-based detection difficult.

Attribution Assessment

Based on code similarities, infrastructure overlap, and tactical patterns, intelligence analysts attribute Moonstone Sleet to the Democratic People's Republic of Korea (DPRK). Specifically, the actor shares significant TTPs with the Lazarus Group (APT38), yet maintains a distinct set of command-and-control (C2) servers and proprietary malware development cycles. The specific focus on aerospace and defense suggests a strategic alignment with Pyongyang's military modernization goals, while the ransomware element suggests a dual mandate of intelligence gathering and currency generation.

Implications

The emergence of Moonstone Sleet represents a shift in the threat landscape where state-sponsored actors increasingly adopt cybercriminal tactics for self-funding. The use of highly convincing social engineering and custom-built software poses a significant risk to R&D departments. Furthermore, the hybrid model of espionage and ransomware complicates incident response, as the initial detection of ransomware may mask a deeper, ongoing data exfiltration campaign. Organizations in the defense supply chain are at particularly high risk of long-term persistence.

Recommendations

To mitigate this threat, organizations should: 1. Implement strict application whitelisting and monitor for unauthorized software installations, particularly gaming or utility apps. 2. Enhance social engineering awareness training for employees in high-value roles, focusing on professional networking site security. 3. Monitor for outbound connections to known suspicious C2 infrastructure identified in the latest Mandiant indicators of compromise (IOCs). 4. Ensure that development environments are isolated from the primary corporate network to prevent lateral movement and credential harvesting.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo