← Back to all threat actors

Moonstone Sleet

Also known as Storm-1789
Tracked as G1036

Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, Lazarus Group, but has differentiated its tradecraft since 2023. Moonstone Sleet is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.

How we source and review actor profiles
Motivation
cybercrime
Sectors
defense, technology, education
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: Storm-1789

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G1036

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Moonstone SleetCanonical Name
Storm-1789Alias
G1036Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...