Introduction
Ruby Sleet is a threat actor linked to North Koreaβs Ministry of State Security. Cerium has been involved in spear-phishing campaigns, compromising devices, and conducting cyberattacks alongside other North Korean threat actors. They have also targeted companies involved in COVID-19 research and vaccine development.
Activities and Tactics
Country of Origin: π°π΅ North Korea
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
Information pending cataloguing.
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- CyberGate
- Cyber Eye RAT
Attribution and Evidence
Country of Origin: North Korea Additional attribution information pending cataloguing.
References
References pending cataloguing.