APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
Moonstone Sleet (aka Storm-1789) · APT Atlas
Actors
/
Nation-state / APT
/
Asia
Moonstone Sleet
APT
KP · North Korea
AKA
Storm-1789
Mandiant
:
UNC4899
DPRK cluster engaged in IT-worker fraud and ransomware development.
Targets
25
Sectors
18
Threat types
2
GIRs covered
0/480
Active since
2023
Pin to atlas
Watch
Share
Export
Also tracked as
2 vendor names · 1 other aliases
Open Rosetta Stone
Mandiant
UNC4899
Microsoft
Moonstone Sleet
UNATTRIBUTED ALIASES
Storm-1789
Victimology
Geographic footprint · 25 countries
Region filter
Export
origin · North Korea
targeted countries · 25
AMERICAS ·
3
Argentina
·
Brazil
·
Canada
EUROPE ·
14
Belgium
·
Germany
·
Denmark
·
Estonia
·
Spain
·
United Kingdom
·
Hungary
·
Italy
·
Netherlands
·
Poland
·
Russia
·
Sweden
·
Slovenia
·
Ukraine
ASIA ·
6
Israel
·
India
·
Japan
·
South Korea
·
Türkiye
·
Vietnam
OCEANIA ·
1
New Zealand
AFRICA ·
1
South Africa
Sectors targeted
18 of 40
Government
100 actors
Defense
72 actors
Aerospace
59 actors
Financial Services
74 actors
Cryptocurrency
21 actors
Healthcare
47 actors
Pharmaceutical
27 actors
Telecom
72 actors
Energy / Utilities
59 actors
Education & Research
62 actors
Manufacturing (man)
50 actors
Media & Journalism
49 actors
Transportation
31 actors
Consulting / Professional Services
35 actors
Industrials / Engineering
29 actors
Consumer Goods / Electronics
20 actors
Agriculture & Food
18 actors
Maritime
24 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
FIN · Financial Fraud
RAN · Ransomware
MITRE ATT&CK · 19 techniques
Reconnaissance
· 3
T1589.002
Email Addresses
T1591
Gather Victim Org Information
T1598
Phishing for Information
Resource Development
· 2
T1583.003
Virtual Private Server
T1587
Develop Capabilities
Initial Access
· 3
T1195.002
Compromise Software Supply Chain
T1566.001
Spearphishing Attachment
Execution
· 1
T1053.005
Scheduled Task
Persistence
· 1
Credential Access
· 1
T1003.001
LSASS Memory
Discovery
· 3
T1016
System Network Configuration Discovery
Impact
· 1
T1486
Data Encrypted for Impact
Command And Control
· 2
T1071.001
Web Protocols
Stealth
· 2
T1027
Obfuscated Files or Information
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
19 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT24
nation-state
China · 3 targets · since 2008
APT27
nation-state
China · 23 targets · since 2010
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1566.003
Spearphishing via Service
T1547.001
Registry Run Keys / Startup Folder
T1033
System Owner/User Discovery
T1217
Browser Information Discovery
T1105
Ingress Tool Transfer
T1140
Deobfuscate/Decode Files or Information