Microsoft says that North Korean hackers, (a group known as Moonstone Sleet) have deployed Qilin ransomware payloads in a limited number of recent attacks.
See also: Qilin Ransomware responsible for Lee Enterprises attack

The activity of this threat group, previously tracked as Storm-1789, initially overlapped with other North Korean attackers such as Diamond Sleet and Onyx Sleet. However, it has since changed its tactics and adapted its tools and attack infrastructure.
Microsoft says Moonstone Sleet hackers target both financial and cyberespionage targets using trojanized software.
Since emerging in August 2022 under the name “ Agenda ,” the Qilin ransomware gang has listed over 300 victims on its Dark Web leak site. However, its Ransomware-as-a-Service ( RaaS ) operation was not particularly active until attacks peaked in late 2023. In December 2023, Qilin affiliates began deploying one of the most advanced Linux cryptojacking tools to target VMware ESXi virtual machines .
See also: Qilin.B ransomware: New version of Qilin with stronger encryption
So far, BleepingComputer has seen ransom ranging from $25,000 to millions, depending on the size of the victims. Qilin ransomware has claimed more than 310 victims since it emerged, including automotive giant Yangfeng, American newspaper publisher Lee Enterprises, Australian Court Services Victoria , and pathology services provider Synnovis.

The latter led to a shutdown that affected several major NHS in London, forcing them to cancel hundreds of procedures and appointments.
In May 2024, Microsoft also linked Moonstone Sleet to a customized ransomware variant called FakePenny. After a successful FakePenny ransomware attack, North Korean hackers were observed demanding a ransom of $6.6 million in BTC.
Moonstone Sleet is not the first North Korean-backed threat group to be linked to ransomware attacks in recent years. In May 2017, the US and UK governments blamed the Lazarus Group for the WannaCry, which crippled hundreds of thousands of computers around the world.
See also: Qilin ransomware: Steals credentials from Chrome browser
Years later, in July 2022, Microsoft and the FBI linked North Korean hackers to the Holy Ghost and the Maui ransomware attacks targeting healthcare organizations.
Source: bleepingcomputer
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
