🇰🇷

Moonstone Sleet

APT Group 8 zero-day CVEs ETDA ✓

Also Known As 3 names

Storm-1789 Group G1036 Stressed Pungsan

Target Countries 42

Countries highlighted in red

United Arab Emirates Argentina Australia Azerbaijan Bangladesh Bahrain Brazil Canada Switzerland Chile China Colombia Germany Dominican Republic Ecuador Egypt France United Kingdom Indonesia Israel India Iraq Italy Japan Cambodia Democratic People's Republic of Korea Republic of Korea Myanmar Mexico Malaysia Netherlands Panama Philippines Poland Saudi Arabia Singapore Thailand Turkey Ukraine United States Vietnam South Africa

Sectors Targeted

blockchain and defense industrial base sectors retail Air Transportation 481 Aerospace Legal Critical infrastructure IT Services Professional Services and media companies Consumer Services Construction Justice, Public Order, and Safety Activities 922 Electricity and critical infrastructure sectors Professional, Scientific, and Technical Services 54 defense printed circuit board manufacturing Healthcare Pharmaceutical government Defense Social Media satellite NAICS:44 44 Aerospace & Defense Agriculture, Forestry, Fishing and Hunting 11 critical infrastructure Information 51 Technology communications equipment Manufacturing Multiple state government Military legal Dating Website oil and gas insurance Research Commodity Contracts Intermediation 523160 Telecommunications 517 Mining, Quarrying, and Oil and Gas Extraction 21 Financial finance Mining Education and Research Academia Software Publishers 5112 Public Administration 92 Telecommunications Construction of Buildings 236 Food and Beverage Freelance software development Internet Publishing and Broadcasting and Web Search Portals 51913 Finance and Insurance 52 Insurance virtual token business) healthcare Multiple (including Fortune 500 firms Agriculture Industrial Control Systems National Security and International Affairs 928 Educational Services 61 Aviation Software Development financial services Computer and Electronic Product Manufacturing 334 ICS equipment and engineering Electric Retail Commercial Banking 52211 local government Insurance Carriers and Related Activities 524 aviation Space Research and Technology 927 professional services military Defence Multiple Industries (Consumer and Enterprise) social media Weather forecasting technology Real Estate Health care Social media Financial Systems dating website Finance manufacturing Professional services crypto NAICS:48 48 Chemical Manufacturing 325 Software Cryptocurrency Aerospace and Defense Industrial Government IT education Business Services Web3 Automotive Financial services Transportation aerospace Financial Technology Financial Services Fintech Critical Infrastructure Aircraft Manufacturing 336411 Media companies financial Asset Management Financial Sector Dating websites Software and information technology Infrastructure NAICS:31 31 Decentralized Finance Automobile Dealers 4411 federal government Utilities 22 media Construction 23 Think Tanks Think tanks Aerospace and defense Hospital Media Other Information Services 519 Information Technology pharmaceutical Satellite communications transportation Education Energy Government agencies education and software development fintech cryptocurrency

Details

Origin 🇰🇷 KR
Last Updated 05 Jun 2024

Malware Families 1

eternal_petya

MITRE ATT&CK 29

T1003 - OS Credential Dumping T1027 - Obfuscated Files or Information T1053 T1055 T1059 T1059.001 - PowerShell T1059.003 - Windows Command Shell T1059.007 - JavaScript T1070 - Indicator Removal on Host T1071 T1102 - Web Service T1105 - Ingress Tool Transfer T1122 T1140 - Deobfuscate/Decode Files or Information T1193 T1195 T1210 T1218 - Signed Binary Proxy Execution T1543.003 T1547 - Boot or Logon Autostart Execution T1555 - Credentials from Password Stores T1566 T1567 T1569 T1571 - Non-Standard Port T1573 T1574 - Hijack Execution Flow T1583 T1588