Moonstone Sleet Strikes: North Korea’s Comedic Ransomware Plot Twist!
Moonstone Sleet, a North Korea-linked APT group, has started using Qilin ransomware in limited attacks, marking a shift from their custom ransomware. Known for targeting financial and cyberespionage victims, Moonstone Sleet now employs this ransomware developed by a RaaS operator, adding a new twist to their cyber antics.

Hot Take:
Looks like Moonstone Sleet just got a “ransom” makeover! North Korea’s notorious cyber group decided to swipe left on their homemade cyber nasties and right on the Qilin ransomware. It’s like trading your mom’s secret meatloaf recipe for a Michelin-star meal prepared by a shady RaaS operator. What’s next, Moonstone? Maybe try a lemonade stand?
Key Points:
- North Korea-linked APT Moonstone Sleet is now using Qilin ransomware.
- Previously, they used custom ransomware tactics for attacks.
- Qilin ransomware known for “double extortion” techniques.
- Moonstone Sleet masquerades as fake companies and developers.
- Qilin ransomware group previously targeted UK healthcare and Ukrainian Ministry of Foreign Affairs.
Already a member? Log in here