logo

Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems

ID: 2f5ba127-4d7f-57e6-8b76-b3ee2a278f56

STIX ID: report--2f5ba127-4d7f-57e6-8b76-b3ee2a278f56

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-01-23

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**MoonPeak (XenoRAT variant) LNK-based campaign targeting South Korean investors and crypto traders:** A malicious campaign observed since January 2026 uses deceptive LNK shortcuts that display XOR-encoded PDF decoys while executing obfuscated PowerShell/VBScript to perform environment checks, download additional GZIP-compressed payloads from GitHub (Living Off Trusted Sites), load payloads into memory, establish persistence via scheduled tasks, and connect to a C2 at 27.102.137.88:443; analysts link the activity to DPRK-affiliated actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.