Pearl Sleet, also known as LAWRENCIUM and previously tracked by Microsoft as DEV-0215, is a North Korea-aligned nation-state threat actor active since at least 2012. The group is associated with espionage and surveillance activity focused primarily on individuals and organizations of strategic interest to the Democratic People's Republic of Korea. Reported targeting has centered on North Korean defectors, religious organizations, and digital, print, and broadcast media, particularly in East Asia. Pearl Sleet is part of Microsoft's North Korea-attributed Sleet cluster naming family. The actor is known for intelligence collection against civil society and media-linked targets rather than financially motivated ransomware operations. Its victimology indicates a strong focus on monitoring dissident communities, information flows, and organizations that may shape narratives or provide support networks related to North Korea. This places the group within the broader DPRK cyber apparatus, but distinct from other North Korean clusters more closely associated with cryptocurrency theft or disruptive operations. High-confidence public reporting identifies Pearl Sleet as a long-running DPRK state activity group. Known aliases include LAWRENCIUM and DEV-0215. No specific sub-groups are established here at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
North Korea-linked nation-state threat actor listed in Microsoft's naming taxonomy mapping.
DPRK-linked cluster mentioned as distinct from earlier 'Lazarus period' lineage; no specific operations described in the content beyond being part of DPRK actor history/lineages.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.