Ruby Sleet is a North Korean state-linked threat actor tracked since at least 2020. The group is associated with cyber operations aligned with DPRK strategic objectives and is known for targeting aerospace and defense-related organizations, including Korean defense contractors. Reported activity indicates a focus on organizations connected to military technology and related supply chains. Ruby Sleet is notable for steadily increasing the sophistication of its phishing and intrusion tradecraft. The actor has used malware signed with legitimate but compromised certificates, distributed trojanized versions of legitimate software including VPN clients and installers, and tailored capabilities to victim environments after researching the specific software and operational context used by targets. The group has also conducted supply-chain compromise, including replacing legitimate software updates with backdoored versions in order to gain access to downstream victims. Observed operations show a combination of initial access through phishing and software supply-chain abuse, followed by post-compromise activity enabled by customized tooling and defense-evasion measures. Ruby Sleet has been linked to successful compromises of aerospace and defense entities, and its operations have been assessed as supporting North Korean military research priorities, including missile and drone-related objectives. Known aliases in the supplied material include Cerium and Ruby Sleet.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.