FakePenny is a custom ransomware family attributed to the North Korea-aligned Moonstone Sleet threat actor. First observed in April 2024, it was deployed against a previously compromised defense technology organization following an intrusion that involved credential and intellectual-property theft. FakePenny consists of loader and encryptor components and was used to demand a multimillion-dollar payment in Bitcoin. Its ransom note exhibited substantial overlap with one associated with NotPetya activity. Moonstone Sleet conducts financially motivated and cyberespionage operations and has targeted software and IT organizations, educational institutions, and defense-industrial-base entities, including aerospace-related companies. The actor commonly gains access through social-engineering operations involving fraudulent companies, recruitment or collaboration lures, trojanized legitimate software, malicious development packages, and a malicious game; FakePenny itself was deployed after compromise for financial extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Another DPRK cluster, Moonstone Sleet, acted similarly by deploying its custom malware FakePenny in 2024."
Last year, Bitdefender revealed that another North Korean threat actor tracked as Moonstone Sleet, which previously dropped a custom ransomware family called FakePenny, had likely targeted several South Korean financial firms with Qilin ransomware.
In April 2024, Microsoft observed Moonstone Sleet delivering a new custom ransomware variant we have named FakePenny ... FakePenny includes a loader and an encryptor.
In April 2024, Microsoft observed Moonstone Sleet delivering a new custom ransomware variant we have named FakePenny ... FakePenny includes a loader and an encryptor.
In April 2024, Microsoft observed Moonstone Sleet delivering a new custom ransomware variant we have named FakePenny ... FakePenny includes a loader and an encryptor.
In April 2024, Microsoft observed Moonstone Sleet delivering a new custom ransomware variant we have named FakePenny ... FakePenny includes a loader and an encryptor.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware deployed by Moonstone Sleet in 2024 in campaigns combining espionage and revenue generation.
A custom ransomware family previously deployed by the North Korean threat actor Moonstone Sleet.
FakePenny is a custom ransomware variant deployed by the North Korean threat actor Moonstone Sleet, used in targeted attacks against defense technology companies.
FakePenny is a ransomware variant attributed to North Korean threat actors, specifically designed to target aerospace and defense organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.