CTIPilot

Moonstone Sleet

actor · actor:moonstone-sleet single-source

Dual-mandate DPRK cluster (espionage plus revenue generation); deployed its own custom malware FakePenny in 2024 and adopted the Qilin ransomware-as-a-service in 2025, within two months of Andariel's own RaaS adoption (Sekoia/Kudelski Security, 2026-09-07).

Coverage timeline
1
first 2026-09-08 → last 2026-09-08
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
research
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-09-08/sekoia-kudelski-dprk-lazarus-umbrella-six-cluster-split · ATT&CK page ↗

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-09-08/sekoia-kudelski-dprk-lazarus-umbrella-six-cluster-split · ATT&CK page ↗

Story timeline

  1. 2026-09-08Sekoia and Kudelski Security split the 'Lazarus umbrella' into six named DPRK clusters, and document two of them adopting commodity ransomware-as-a-service within two months of each other
    researchA Swiss research lab co-publishes the DPRK actor-tracking update: two nominally-espionage clusters rented commodity ransomware in the same window

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

collaborates with

Where this entity is cited

  • research1

Source distribution

  • kudelskisecurity.com1 (50%)
  • sekoia.com1 (50%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Moonstone Sleet (1)

2026-09-08 · view entry permalink →

NOTABLENATOB2

Sekoia and Kudelski Security split the 'Lazarus umbrella' into six named DPRK clusters, and document two of them adopting commodity ransomware-as-a-service within two months of each other

Sekoia's TDR team and Kudelski Security, a Switzerland-based research firm, jointly published a reassessment of how North Korea's offensive-cyber apparatus is organized (Kudelski Security, 2026-09-07). The authors now track the historical "Lazarus umbrella" as six distinct sub-clusters (TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima, the last already tracked here as an alias of the North Korean fraudulent-IT-worker cluster) each carrying a different primary mandate spanning strategic espionage, dual espionage-and-revenue operations, and pure financially motivated crime (Kudelski Security, 2026-09-07). The espionage-focused clusters under GRIB (formerly RGB), TEMP.Hermit among them, are the authors' own described inheritors of both the historical Lazarus umbrella and the Kimsuky cluster's lineage, even where their precise bureau affiliation is debated within the CTI community (Kudelski Security, 2026-09-07). The authors date the Lazarus umbrella's internal reorganization into specialized sub-clusters to a 2018–2023 transition phase alongside the global expansion of the cryptocurrency market, out of which APT38 itself emerged as the financially-motivated sub-cluster; APT38 has since, per the authors' own current research, further split into two of these (CryptoCore and Jade Sleet) both exclusively financially motivated and focused on cryptocurrency, Web3 and blockchain targets, though the authors do not date this more recent split.

The most defender-relevant finding is a documented pattern of commodity-ransomware adoption by nominally espionage-focused units: Andariel, a dual-mandate cluster, used its own custom ransomware (Maui, H0lyGh0st) and separately collaborated with the criminal Play ransomware-as-a-service operation in 2024, citing prior reporting from Unit 42; Moonstone Sleet deployed its own custom malware (FakePenny) the same year and then adopted the Qilin ransomware-as-a-service in 2025, within two months of Andariel's own RaaS adoption (Kudelski Security, 2026-09-07). The authors note it is "interesting" that the two clusters integrated RaaS into their campaigns within two months of each other, a single observed timing overlap, not a claimed broader trend, though it is consistent with the general possibility that DPRK clusters rent commodity ransomware infrastructure alongside, or instead of, running only bespoke tooling.

The report also states that "Reaper" (already tracked here as an alias of ScarCruft/APT37) is the cluster aligned with North Korea's newly renamed National Intelligence Agency (formerly the Ministry of State Security, renamed June 2026), tasked with surveillance of defectors and South Korean NGOs and activists. Kudelski Security's own separate prior research, cited in this report, found that DPRK fake-IT-worker infrastructure and offensive-APT infrastructure share the same VPN exit nodes, a concrete pivot point for correlating IT-worker-fraud indicators against APT intrusion infrastructure (Kudelski Security, 2026-09-07). Separately, the report documents a Cambodia-based money-laundering hub, the Huione Group (flagged by the US Treasury's FinCEN as a primary money-laundering concern) whose executives the authors say have shown indications of direct ties to North Korean actors, with an estimated USD 37.6 million in DPRK-linked cryptocurrency laundered through it between 2021 and 2025 via stablecoins and technical tooling that let North Korea convert illicit proceeds into ostensibly legitimate assets (Kudelski Security, 2026-09-07).

We notably made our clustering evolved by splitting the Lazarus umbrella into six distinct sub-clusters: TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, and Famous Chollima.

Sekoia TDR team / Kudelski Security

Of note, Andariel is particular as it used custom ransomware (Maui and H0lyGh0st) for financial theft, as well as ransomware-as-a-service (RaaS) developed by an operator of the Russian cybercrime ecosystem. It was notably observed collaborating with Play in 2024. Another DPRK cluster, Moonstone Sleet, acted similarly by deploying its custom malware FakePenny in 2024, but also the Qilin RaaS in 2025. It is interesting to note that the two clusters integrated RaaS in their campaigns within two months of each other.

Kudelski Security observed that fake IT workers and offensive teams often share the same VPN exit nodes.

Kudelski Security

Builds on: 2026-08-28/kudelski-bismarck-dprk-it-worker-gambling-fakecalls-overlap · 2026-09-03/kimsuky-seafood-invoice-lnk-backblaze-b2-c2 · 2026-09-07/rapid7-ted-backdoor-curlrat-dprk-haproxy

research08 Sep 04:41Zsingle-sourceOpen finding ↗