FakePenny is a custom ransomware family attributed to the North Korea-aligned threat actor Moonstone Sleet. First observed in April 2024, it comprises a loader and an encryptor and is deployed following compromise to support financially motivated extortion. Moonstone Sleet used FakePenny against a defense technology company after an earlier intrusion, demanding a multimillion-dollar payment in Bitcoin. The ransom note exhibited overlap with wording associated with NotPetya. Moonstone Sleet conducts both cyberespionage and revenue-generating operations and has targeted software and IT organizations, educational institutions, and the defense industrial base, including aerospace-related organizations. The actor commonly gains access through elaborate social-engineering operations involving fraudulent companies, job and collaboration lures, trojanized legitimate software, malicious developer packages, and a weaponized game; FakePenny is a post-compromise ransomware payload rather than the initial-access component of those campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Moonstone Sleet — double mandat (espionnage + revenus), a déployé FakePenny et le RaaS Qilin en 2025.
Last year, Bitdefender revealed that another North Korean threat actor tracked as Moonstone Sleet, which previously dropped a custom ransomware family called FakePenny, had likely targeted several South Korean financial firms with Qilin ransomware.
In April 2024, Microsoft observed Moonstone Sleet delivering a new custom ransomware variant we have named FakePenny ... FakePenny includes a loader and an encryptor.
In April 2024, Microsoft observed Moonstone Sleet delivering a new custom ransomware variant we have named FakePenny ... FakePenny includes a loader and an encryptor.
In April 2024, Microsoft observed Moonstone Sleet delivering a new custom ransomware variant we have named FakePenny ... FakePenny includes a loader and an encryptor.
In April 2024, Microsoft observed Moonstone Sleet delivering a new custom ransomware variant we have named FakePenny ... FakePenny includes a loader and an encryptor.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware deployed by Moonstone Sleet in 2025 as part of its revenue-generating operations.
Custom malware deployed by Moonstone Sleet in 2024 in campaigns combining espionage and revenue generation.
A custom ransomware family previously deployed by the North Korean threat actor Moonstone Sleet.
FakePenny is a custom ransomware variant deployed by the North Korean threat actor Moonstone Sleet, used in targeted attacks against defense technology companies.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.