Full Report
Microsoft says a North Korean hacking group tracked as Moonstone Sleet has deployed Qilin ransomware payloads in a limited number of attacks. [...]
Analysis Summary
# Threat Actor: Moonstone Sleet (Associated with North Korean State-Sponsored Activity)
## Attribution & Identity
* **Identification:** North Korean hackers, linked by Microsoft.
* **Aliases/Associations:** Linked to the deployment of the Qilin ransomware and a custom FakePenny ransomware variant. Historically associated with other North Korean threat activities, including Lazarus Group (WannaCry) and Holy Ghost/Maui ransomware operations.
## Activity Summary
Microsoft recently linked Moonstone Sleet activity to the deployment of Qilin ransomware. In May 2024, Microsoft also connected this group to a custom **FakePenny** ransomware variant, demanding a ransom of $6.6 million in BTC after a successful attack. Historically, North Korean actors have been blamed for major campaigns such as the 2017 **WannaCry** outbreak and the **Holy Ghost/Maui** ransomware operations targeting healthcare.
## Tactics, Techniques & Procedures
* **Ransomware Deployment:** Utilizing both the Qilin ransomware strain and a custom **FakePenny** ransomware variant.
* **Extortion:** Demanding large ransom amounts (e.g., $6.6 million in BTC for FakePenny).
* **Historical Context:** Associated with previous major ransomware outbreaks like WannaCry and the Maui ransomware operation.
* **MITRE ATT&CK IDs:** Not explicitly listed in the provided text, but the activity involves Ransomware Execution.
## Targeting
* **Sectors:** Healthcare/Pathology Services, Automotive, Media/Publishing, Government/Judicial Services.
* **Geography:** Global, with specific victims mentioned in the UK, US, and Australia.
* **Victims:** Yangfeng (automotive), Lee Enterprises (publisher), Court Services Victoria (Australia), Synnovis (pathology services leading to NHS hospital disruption).
## Tools & Infrastructure
* **Malware families used:** Qilin Ransomware, Custom FakePenny Ransomware variant.
* **Infrastructure (C2, domains, IPs):** No specific IP addresses or domains were provided/defanged in the summary text.
## Implications
Moonstone Sleet represents a persistent and evolving threat from North Korea, confirming the increased tactical adoption of established and bespoke ransomware strains (Qilin, FakePenny) by state-sponsored actors. Their targeting is broad, hitting critical infrastructure sectors like healthcare and government services, suggesting a motive driven heavily by illicit financial gain, characteristic of DPRK operations.
## Mitigations
* (No specific, explicit mitigation steps were detailed in the provided article snippet, other than the implication of defense against ransomware delivery and execution.)