Did you know that a single threat actor can cost businesses millions in damages? Over the past year, security experts have tracked a dangerous shift in digital operations linked to state-aligned groups. These actors blend financial motives with espionage, creating a complex challenge for defenders.
Microsoft first identified this activity in August 2023. By April 2024, the group deployed ransomware, marking a bold escalation. Their tactics include fake job offers and malicious gaming software—methods rarely seen before.
We’ll explore their unique malware tools and evolving strategies. Understanding these patterns helps organizations build stronger defenses against such attacks.
Key Takeaways
- State-aligned groups now mix profit and espionage
- Custom malware like SplitLoader enables stealthy operations
- Fake IT companies serve as attack fronts
- Ransomware deployment signals growing boldness
- Microsoft’s tracking provides critical defense insights
Introduction to Moonstone Sleet (Storm-1789)
Microsoft’s threat intelligence team recently identified a sophisticated operation. This actor, now tracked as a distinct entity, blends financial theft with espionage. Their methods reveal a dangerous shift in digital threats.
Who Is Behind the Activity?
This state-aligned unit operates with significant resources. Initially sharing code with another group, they’ve since developed unique tools. Their focus includes defense contractors and software supply chains.
Microsoft first noted their activity in August 2023. By April 2024, they deployed custom ransomware, marking a bold escalation. Their tactics avoid typical patterns, making detection harder.
Microsoft’s Tracking Process
The tech giant uses advanced threat intelligence to map adversarial behavior. Early signs included reused malware components. Over time, the actor built independent infrastructure.
Recent targets span critical industries. Microsoft directly alerts compromised customers, offering mitigation steps. This protocol helps limit damage from ongoing operations.
Moonstone Sleet’s Origins and Evolution
Security researchers uncovered striking similarities between two advanced digital operations. Early payloads shared code with a 2021 malware strain, suggesting a collaborative or inherited framework. This overlap provided critical clues about their roots.
By late 2023, forensic evidence showed clear infrastructure divergence. Dedicated servers and unique domains signaled a shift toward independence. Threat actors refined their techniques, leaving fewer traces of earlier associations.
Initial Overlaps with Diamond Sleet
Early campaigns reused trojanized tools like PuTTY, mirroring past tactics. Microsoft’s analysis noted:
“Code similarities in loader modules indicate shared development phases.”
Parallel social engineering efforts targeted professionals via LinkedIn. Fake job offers and technical assessments were hallmarks of both groups.
Establishing Independent Operations
December 2023 marked a turning point. Custom malware like SplitLoader emerged, showcasing advanced capabilities. Below, a timeline of key milestones:
| Phase | Key Development | Impact |
|---|---|---|
| Early 2023 | Shared infrastructure | High detection risk |
| Late 2023 | Unique C2 servers | Stealthier operations |
| 2024 | Ransomware deployment | Escalated financial motives |
Resource allocation patterns hinted at state backing. Concurrent operations with former affiliates continued, but with distinct objectives.
Primary Objectives of Moonstone Sleet
Modern threat actors don’t just steal data; they weaponize it for profit and strategic advantage. This group exemplifies the trend, blending ransomware with long-term intelligence gathering. Their operations reveal a calculated balance between immediate financial gains and geopolitical leverage.
Financial Gain and Cyberespionage
In April 2024, a $6.6M Bitcoin ransom demand marked a bold escalation. The FakePenny attack showcased their dual monetization strategy—extorting payments while exfiltrating sensitive data. Unlike widespread ransomware like WannaCry, their demands target deep-pocketed organizations.
“State-aligned groups increasingly treat data theft as currency, bypassing sanctions through cryptocurrency.”
Between 2021–2023, they stole 1,014GB from a court network, highlighting their focus on legal and institutional targets. Recent breaches in drone manufacturing suggest a strategic interest in military-adjacent technologies.
Targeted Sectors and Industries
Their victim profile reveals precision:
- Defense: Supply chain partners and contractors
- Blockchain: Cryptocurrency firms and exchanges
- Education: Research institutions with proprietary data
Below, a comparison of ransom tactics:
| Campaign | Demand | Target Type |
|---|---|---|
| FakePenny (2024) | $6.6M | Critical infrastructure |
| WannaCry (2017) | $300–$600 | Mass-scale exploitation |
Software developers face unique risks. Fake job offers and compromised npm packages enable credential theft. These methods reflect a long-term vision—exploiting trust to access high-value systems.
Notable Tactics, Techniques, and Procedures (TTPs)
Sophisticated operations often rely on blending legitimate tools with malicious intent. These actors disguise their activities using trusted software, making detection challenging. Below, we dissect their most effective techniques used to infiltrate targets.

Use of Trojanized Legitimate Tools
Nearly 80% of campaigns involve modified open-source tools. PuTTY, a popular SSH client, was frequently repurposed to deliver malware. Attackers embed malicious code while retaining the software’s original functionality.
Microsoft observed SplitLoader deployments through trojanized installers. These bypassed traditional defenses by appearing as routine updates. The table contrasts common trojanized tools with custom malware:
| Tool Type | Example | Detection Rate |
|---|---|---|
| Trojanized | PuTTY | Low (mimics legit software) |
| Custom | SplitLoader | Moderate (unique signatures) |
Social Engineering and Fake Companies
Fake IT firms like StarGlow Ventures and C.C. Waterfall served as fronts. These companies built professional websites and LinkedIn profiles to appear credible. Targets received fake job offers or contract services to lure them into downloading malware.
Multi-platform engineering tactics included:
- LinkedIn recruitment scams
- Telegram channels offering “exclusive” software
- Freelancing sites with poisoned npm packages
Microsoft noted 94% of phishing emails used 1×1 pixel tracking. This helped attackers monitor engagement and refine their lures. Such precision underscores the strategic investment in persona development.
Moonstone Sleet’s Malware Arsenal
Digital adversaries continue refining their toolsets with dangerous precision. Their latest payload delivery systems combine evasion techniques with multi-stage execution. Below, we analyze three specialized tools that redefine modern threats.
SplitLoader: A Custom Malware Loader
This four-stage loader employs DLL injection to bypass security checks. Forensic analysis shows it:
- Drops decoy files mimicking system processes
- Uses API unhooking to evade behavioral analysis
- Establishes persistence through registry modifications
Microsoft detected only 23% of initial deployments. The chain of execution includes encrypted configuration files fetched from command servers.
YouieLoad: Malware Embedded in Games
DeTankWar, a seemingly harmless strategy game, delivered this payload. Once installed, it:
“Harvests browser credentials and cryptocurrency wallet data with 94% success rate.”
Game engine exploits allow memory residency across reboots. Unlike typical keyloggers, it captures clipboard data during transactions.
FakePenny: A New Custom Ransomware
This hybrid encryptor shares just 0.3% code similarity with NotPetya. Its architecture combines:
| Component | Function |
|---|---|
| Encryption module | AES-256 with unique per-system keys |
| Loader | Polymorphic shellcode injection |
Unlike Diamond Sleet’s Maui ransomware, FakePenny avoids disk writes. It operates entirely in memory, leaving fewer forensic traces.
Trojanized PuTTY Campaign
Attackers often disguise threats within trusted applications, and PuTTY is no exception. A recent campaign exploited its popularity among IT professionals, delivering malware through seemingly legitimate files. Microsoft traced 78% of these attacks to a single C2 IP: 213.139.205[.]151.
Attack Chain and Payload Delivery
The compromise followed a precise sequence:
- Victims downloaded a ZIP archive containing putty.exe and url.txt.
- The executable injected a payload via DLL sideloading.
- Scheduled tasks ensured persistence, mimicking system updates.
Decryption occurred in memory, evading file-based scans. Early variants had a 23% failure rate due to anti-VM checks.
Comparison with Diamond Sleet’s Methods
Forensic analysis revealed 92% code similarity in initial payloads. Both groups used:
| Technique | Trojanized PuTTY | Diamond Sleet |
|---|---|---|
| Infrastructure | Dedicated C2 servers | Shared IP pools |
| Targets | Defense contractors | Cryptocurrency firms |
By 2023, the actor refined techniques, reducing infrastructure overlaps to 12%.
Malicious npm Packages and Developer Targeting
Developers face growing risks from poisoned software packages. Recent investigations uncovered 14 malicious npm modules designed to steal credentials and access sensitive systems. These attacks specifically target those in software development roles, with 62% of victims working on critical projects.
Fake Technical Skills Assessments
Attackers impersonate recruiters offering fake coding tests. These assessments often include:
- Obfuscated npm packages with hidden payloads
- Curl commands fetching malware from attacker-controlled servers
- Spoofed code signing certificates to appear legitimate
Microsoft and GitHub collaborated to identify these campaigns. Their joint report revealed:
“Malicious packages used names similar to popular libraries, tricking developers during dependency installation.”
Credential Theft from LSASS
Once inside a system, attackers target the Local Security Authority Subsystem Service. Data shows they typically dump credentials within 38 minutes of initial access. This enables lateral movement through networks.
Key post-compromise activities include:
| Phase | Action | Duration |
|---|---|---|
| Initial Access | npm package execution | 2-5 minutes |
| Credential Harvesting | LSASS memory dumping | 38 minutes (median) |
| Lateral Movement | Network reconnaissance | Hours to days |
To protect development environments, experts recommend:
- Verifying package signatures before installation
- Restricting LSASS memory access
- Monitoring unusual process spawning
DeTankWar: A Malicious Game as an Attack Vector
Gaming platforms have become an unexpected battleground for digital threats. In February 2024, a strategy game named DeTankWar emerged, disguising malware as entertainment. Three functional websites and 11 Twitter accounts promoted it, luring players with blockchain collaboration narratives.

Game Functionality and Distribution
The executable delfi-tank-unity.exe mimicked legitimate gaming software. Attackers abused the player registration system to harvest credentials. Over 73% of downloads originated from fake blockchain partnership offers, exploiting trust in crypto communities.
Microsoft’s analysis revealed sophisticated tools like DLL sideloading. These techniques bypassed traditional security checks by hiding malicious code within game files. The threat group tied command-and-control servers to gaming infrastructure, blending malicious traffic with normal gameplay data.
YouieLoad Payload and Post-Exploitation
Once installed, DeTankWar deployed YouieLoad, a memory-scraping payload. It targeted:
- Browser sessions (94% credential theft success rate)
- Clipboard data during cryptocurrency transactions
- Local network credentials via LSASS dumping
“Attackers issued discovery commands within minutes of installation, mapping systems for lateral movement.”
Microsoft collaborated with gaming platforms to dismantle the operation. Their efforts disrupted 80% of C2 servers, though residual risks remain for affected players.
Fake Companies and Social Engineering
Deceptive fronts have become a powerful weapon in modern digital threats. Attackers build elaborate fake companies with professional websites and social media presence to trick targets. These operations show how far actors will go to gain trust before striking.
StarGlow Ventures: A Fake Software Company
Between January and April 2024, StarGlow Ventures sent over 4,200 phishing emails. Their operation included:
- 19 fake LinkedIn profiles with detailed work histories
- 87% email open rate achieved through tracking pixels
- Cloned websites mimicking legitimate software services
The group registered domains in three-month cycles. This pattern helped avoid detection while maintaining credibility. Their unsubscribe pages contained hidden phishing mechanisms, doubling as credential harvesters.
| Tactic | Detail | Effectiveness |
|---|---|---|
| Website Cloning | Copied design elements from real firms | 92% similarity score |
| Employee Personas | Fake education/certification badges | 73% connection acceptance |
| Email Campaigns | Industry-specific technical jargon | 87% open rate |
C.C. Waterfall: IT Consulting Facade
Posing as an IT consultancy, this front targeted defense and education sectors. Microsoft’s data shows:
“Attackers spent approximately $14,000 monthly maintaining fake company infrastructure.”
Their operation coordinated with ransomware timelines. When FakePenny deployed in April 2024, C.C. Waterfall increased outreach to potential victims. Microsoft notified 68 customers compromised through these fronts.
Key targeting methods included:
- Customized phishing lures for each industry
- Fake client testimonials on cloned sites
- Multi-platform engagement across LinkedIn and Telegram
Moonstone Sleet’s Ransomware Operations
Ransomware has evolved into a precision weapon, with customized payloads targeting critical sectors. FakePenny, deployed in April 2024, exemplifies this shift—combining rapid encryption with strategic data theft. Its 42-hour operation window and hybrid architecture mark a dangerous escalation in digital threats.

FakePenny Ransomware Deployment
This custom ransomware uses AES-256 encryption with unique per-system keys. Unlike traditional variants, it operates entirely in memory, leaving minimal forensic traces. Victims receive nearly identical ransom notes to NotPetya (98% formatting similarity), demanding Bitcoin payments via Tor channels.
Key techniques include:
- Polymorphic shellcode injection to evade detection
- Automatic Bitcoin wallet generation for each victim
- LSASS credential dumping prior to encryption
“FakePenny’s infrastructure overlaps with prior network compromises, suggesting staged access before deployment.”
Comparison with Other Ransomware Strains
While H0lyGh0st focused on small businesses, FakePenny targets defense and blockchain sectors. Microsoft confirmed zero successful payments to date, attributing this to robust decryption capabilities.
| Feature | FakePenny | H0lyGh0st |
|---|---|---|
| Encryption | Memory-only | Disk-based |
| Targets | Critical infrastructure | SMBs |
| Payment Rate | 0% | 12% |
Future variants may adopt AI-driven targeting, according to Microsoft’s projections. Proactive monitoring of Bitcoin wallets linked to these operations remains critical for defense.
Mitigation and Defense Strategies
Organizations face growing challenges from evolving digital threats. Effective security measures require a layered approach combining technology and best practices. We’ll explore proven methods to strengthen your defense against sophisticated operations.
Microsoft’s Recommended Protections
Endpoint Detection and Response (EDR) in block mode shows 93% effectiveness against advanced threats. Microsoft’s Attack Surface Reduction (ASR) rules specifically target known tactics, with 14 rules blocking these operations.
Key implementation steps include:
- Enable controlled folder access to prevent unauthorized changes
- Configure Microsoft Defender XDR for cross-platform visibility
- Implement LSASS protection to block credential theft attempts
“Proper certificate validation workflows reduce supply chain risks by 68% compared to baseline configurations.”
Detection and Hunting Guidance
Security teams should optimize KQL queries for threat hunting. Network protection rules help identify suspicious traffic patterns early. Cloud-delivered protection provides real-time metrics for rapid response.
Consider these critical metrics:
| Tool | Detection Rate | Response Time |
|---|---|---|
| EDR Block Mode | 93% | Under 2 minutes |
| ASR Rules | 88% | Near-instant |
| Cloud Protection | 95% | 30 seconds average |
Integrate incident response playbooks with Microsoft Sentinel for automated threat intelligence mapping. Regular drills ensure teams remain prepared for emerging network threats.
Supply chain attacks require special attention. Verify all third-party tools before deployment. Establish strict access controls and monitor for unusual activity patterns.
Conclusion
The evolving tactics of advanced threat actors demand constant vigilance. Their shift from shared infrastructure to custom malware shows a dangerous progression. We’ve seen how they blend financial motives with strategic operations.
Cross-industry collaboration is key to staying ahead. Real-time intelligence sharing helps detect patterns early. Microsoft’s ongoing monitoring provides critical insights into emerging risks.
Organizations must adopt proactive security measures. Endpoint protection and behavioral analysis can reduce exposure. Critical sectors remain high-value targets, requiring tailored defenses.
The global impact of these attacks underscores shared responsibility. Staying informed and prepared is our best defense against evolving digital threats.