Citrine Sleet is a North Korean government-linked threat actor tracked by Microsoft under its "Sleet" naming convention for DPRK-associated cyber operators. The actor has been identified as participating in large-scale cryptocurrency theft activity attributed to North Korean operators. This activity aligns with broader DPRK cyber campaigns that use illicit cyber operations to generate revenue for state priorities. Publicly available information in this context does not provide a distinct technical profile, malware set, or victimology unique to Citrine Sleet beyond its involvement in cryptocurrency heists alongside other North Korean Sleet clusters such as Jade Sleet and Sapphire Sleet. Based on the available facts, Citrine Sleet should be understood as part of the North Korean cyber ecosystem focused on financially motivated operations, particularly theft from the cryptocurrency sector.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.