Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1036
MITRE ATT&CK Group

Moonstone Sleet (G1036)

Storm-1789
ShareXLinkedInRedditHN

[Moonstone Sleet](https://attack.mitre.org/groups/G1036) is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-linked entity, [Lazarus Group](https://attack.mitre.org/groups/G0032), but has differentiated its tradecraft since 2023. [Moonstone Sleet](https://attack.mitre.org/groups/G1036) is notable for creating fake companies and personas to interact with victim entities, as well as developing unique malware such as a variant delivered via a fully functioning game.(Citation: Microsoft Moonstone Sleet 2024)

▪Techniques used (30)

T1587.001MalwareT1033System Owner/User DiscoveryT1071.001Web ProtocolsT1585.002Email AccountsT1589.002Email AddressesT1140Deobfuscate/Decode Files or InformationT1591Gather Victim Org InformationT1053.005Scheduled TaskT1547.001Registry Run Keys / Startup FolderT1204.002Malicious FileT1566.001Spearphishing AttachmentT1027Obfuscated Files or InformationT1583.003Virtual Private ServerT1105Ingress Tool TransferT1016System Network Configuration DiscoveryT1598.003Spearphishing LinkT1003.001LSASS MemoryT1608.001Upload MalwareT1598Phishing for InformationT1195.002Compromise Software Supply ChainT1569.002Service ExecutionT1583.001DomainsT1217Browser Information DiscoveryT1566.003Spearphishing via ServiceT1486Data Encrypted for ImpactT1585.001Social Media AccountsT1587Develop CapabilitiesT1082System Information DiscoveryT1027.013Encrypted/Encoded FileT1027.009Embedded Payloads

▪Software used (1)

S1242Qilinmalware
G1036on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.