Opal Sleet — APT Profile

Opal Sleet is Microsoft's designation for a North Korean espionage cluster; Microsoft's published actor mapping files it alongside the names OSMIUM, Velvet Chollima, Planedown, Konni and APT43, while Symantec research uses the label Vedalia for the same tooling. Attribution within the DPRK ecosystem is genuinely contested here: Malpedia ties the KONNI remote access trojan that supplies the cluster's best-known alias only tentatively to APT37, whereas Microsoft places it in the Kimsuky and APT43 lineage. KONNI has circulated since early 2014 by Malpedia's dating, and campaigns built on it have struck South Korean political organisations, Russian foreign-ministry and diplomatic entities during 2022, and — in 2024 research from DCSO — a trojanised installer for Russian consular software. NSFOCUS reported that the operators adopted the WinRAR archive flaw CVE-2023-38831 within weeks of its disclosure and aimed it at South Korean cryptocurrency firms, dropping KonniRAT to seize hosts and pull data off them. Symantec documented a further delivery trick in April 2024, in which oversized shortcut files padded with whitespace and disguised by double extensions concealed the PowerShell commands that launched the payload.

Also tracked as

OSMIUM, Vedalia

Vendor research

Read the full analysis on IntelFusions