Moonstone Sleet: Korean star with dangerous software

June 14, 2024
1 min read

TLDR:

North Korean threat actors, such as Moonstone Sleet, are distributing malicious packages through the NPM registry to compromise supply chains. A new threat actor, Moonstone Sleet, has emerged with similar tactics. Microsoft has highlighted the emergence of Moonstone Sleet and their TTPs.

New Moonstone Sleet North Korean Actor Deploying Malicious Open Source Packages

In December 2023, North Korean threat actors, particularly Jade Sleet, were reported to be compromising supply chains through the open-source ecosystem by distributing malicious packages through the public npm registry. Moonstone Sleet, a new threat actor, has emerged with similar tactics, posing ongoing threats to the open-source software supply chain.

Key Findings:

  • Continued publication of malicious packages on NPM
  • Moonstone Sleet targeting open-source software with similar tactics to other North Korean groups
  • Microsoft highlighting the emergence of Moonstone Sleet and their TTPs

Malicious NPM Packages:

Moonstone Sleet distributes malware through malicious NPM packages on the public NPM registry, increasing the exposure of developers to potential compromise. The packages attributed to Jade Sleet and Moonstone Sleet exhibit distinct differences in code style and structure, reflecting varying strategies used by different threat groups.

Recent Developments:

Microsoft has identified Moonstone Sleet as a rising North Korean threat actor utilizing tactics resembling other state-sponsored actors. Moonstone Sleet has been spreading malicious packages through freelancing websites, LinkedIn, and the public npm registry, elevating the threat to a wider audience and showcasing evolving tactics.

Changes in Attack Flow:

In the second quarter of 2024, the complexity of malicious packages increased, with attackers adding obfuscation and targeting Linux systems as well. The ongoing publication of malicious packages underscores the persistent nature of North Korean threat actors’ campaign, emphasizing the importance of collaboration in the security community to identify and thwart these attacks.

Latest from Blog

Top 20 Linux Admin Tools for 2024

TLDR: Top Linux Admin Tools in 2024 Key points: Linux admin tools streamline system configurations, performance monitoring, and security management. Popular Linux admin tools include Webmin, Puppet, Zabbix, Nagios, and Ansible. Summary

Bogus job tempts aerospace, energy workers

TLDR: A North Korean cyberespionage group is posing as job recruiters to target employees in aerospace and energy sectors. Mandiant reports that the group uses fake job descriptions stored in malicious archives