UAT-5394
2024-08-21 • Cisco Talos • MoonPeak malware from North Korean actors unveils…
Cisco Talos, the naming company, first documented UAT-5394 in an August 2024 report, later corroborated by a September 2024 blog post from another researcher summarizing the same findings and malware samples. Talos describes UAT-5394 as a North Korean state-sponsored nexus of threat actors developing and distributing MoonPeak, a remote access trojan forked from the open-source XenoRAT project; an earlier variant of this activity was first disclosed by AhnLab in a spear-phishing campaign that Talos assessed evolved into MoonPeak. Talos observed tactical and infrastructure overlaps with the Kimsuky group but stated it lacked sufficient technical evidence to confirm a link, so it tracks UAT-5394 as an independent cluster pending further intelligence. In mid-2024 the actor shifted from hosting payloads on legitimate cloud storage to servers it owned and controlled, likely to avoid takedowns, and Talos mapped an extensive network of staging servers, command-and-control servers, and dedicated virtual machines used to test MoonPeak implants before deployment. MoonPeak was observed evolving iteratively, adding obfuscation and pairing specific malware builds to specific C2 server versions to block unauthorized or rogue connections.
-
43
Related Actors
-
2
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster