#MoonPeak

Malware/Tool

2024-08-21 • MoonPeak malware from North Korean actors unveils new details on attacker infrastructure

MoonPeak is a custom remote access trojan derived from the open-source XenoRAT codebase and associated with North Korean activity, including UAT-5394 and reporting on Kimsuky infrastructure. Observed Windows delivery used disguised LNK files aimed at game-industry personnel or Korean investors. Opening a shortcut displayed a decoy PDF and ran hidden, obfuscated PowerShell that checked for analysis environments, collected system information, downloaded further scripts or payloads, and established scheduled-task persistence. One chain generated aes.js to obtain a cookie, unpacked GZIP data disguised as RTF, and loaded MoonPeak. The RAT communicated with command-and-control servers over asynchronous sockets; reported infrastructure included dedicated servers and ports 9999, 9966, and 8936.

Tagged Reports

« Back