Listen to this Post
Microsoft recently unveiled that the North Korean hacking group Moonstone Sleet, previously known as Storm-1789, has begun deploying Qilin ransomware in a select number of attacks since February 2025. This marks a significant shift in the group’s tactics, as they had exclusively used their own custom ransomware tools until now. This new development highlights the increasing complexity and adaptability of North Korean cyber threats.
the Attack and Group Activity
Since late February 2025, Microsoft’s security experts have tracked Moonstone Sleet’s deployment of the Qilin ransomware against several organizations. This marks the first time they have utilized ransomware developed by a Ransomware-as-a-Service (RaaS) operator, diverging from their usual approach of using bespoke ransomware tools. Moonstone Sleet is a North Korean cyber espionage group that has previously focused on financial targets and espionage, using various tactics like trojanized software (e.g., PuTTY), malicious npm packages, fake companies, and targeted social engineering through platforms like LinkedIn and Telegram.
Qilin ransomware, which has been active since 2022, has claimed more than 300 victims on its dark web site. Notable victims include large organizations like Yangfeng, Lee Enterprises, and the Court Services Victoria, with attacks causing disruptions in sectors like healthcare. This move by Moonstone Sleet to use Qilin ransomware showcases their adaptation to new methods, possibly to increase the scale and impact of their attacks.
Previously, in 2024, Microsoft had linked Moonstone Sleet to the FakePenny ransomware attacks. Their affiliation with ransomware operations goes back years, with North Korean-backed groups like the Lazarus Group being responsible for the infamous WannaCry attack in 2017.
What Undercode Says:
The involvement of Moonstone Sleet in Qilin ransomware attacks is another escalation in the growing cyber threat landscape from North Korea. It is becoming increasingly clear that North Korean hackers are diversifying their tactics, adapting new tools, and collaborating with RaaS operators to maximize the impact of their operations. Their ability to seamlessly integrate with established ransomware networks, such as Qilin, speaks volumes about the sophistication and scalability of their operations.
Historically, North Korean-backed groups have been primarily focused on financial theft, cyber espionage, and disruption of critical infrastructure. Their motivations remain rooted in state-sponsored activities aimed at generating revenue, stealing sensitive information, and destabilizing enemy countries. The use of Qilin ransomware signals a shift in the group’s attack methods, as they are not only deploying more advanced encryption techniques but also targeting larger and more varied sectors globally.
The Qilin ransomware itself, having caused significant damage since its emergence, further underscores the threat posed by Moonstone Sleet’s evolving tactics. Ransom demands from Qilin range from $25,000 to several million dollars, based on the size of the victim. This evolving nature of the ransomware threat and its ability to compromise both Windows and Linux systems (including VMware ESXi virtual machines) demonstrates a major step forward in terms of sophistication.
The fact that Moonstone Sleet hackers are leveraging social media platforms like LinkedIn, Telegram, and freelancing networks to gain access to their targets showcases the continuing threat posed by social engineering in modern cyber attacks. These platforms, often viewed as safe spaces for business and professional networking, are becoming prime targets for cybercriminals looking to exploit human vulnerabilities.
The larger implication here is the shifting global landscape of cybercrime. While many hackers previously operated in isolation or small-scale operations, the rise of ransomware-as-a-service platforms and their utilization by state-backed actors indicates a professionalization of cybercrime. Moreover, the increasing frequency of ransomware attacks on healthcare organizations and essential services highlights how cybercriminals are willing to impact not just the economy, but also public health and safety.
Fact Checker Results:
– Moonstone
- The Qilin ransomware has already been linked to over 310 victims, including large global corporations and healthcare services.
- The attack on healthcare organizations, specifically the NHS in London, emphasizes the growing risk ransomware poses to critical infrastructure globally.
References:
Reported By: https://www.bleepingcomputer.com/news/security/microsoft-north-korean-hackers-now-deploying-qilin-ransomware/
Extra Source Hub:
https://www.quora.com/topic/Technology
Wikipedia: https://www.wikipedia.org
Undercode AI
Image Source:
OpenAI: https://craiyon.com
Undercode AI DI v2





