Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems
ID: 2f5ba127-4d7f-57e6-8b76-b3ee2a278f56
STIX ID: report--2f5ba127-4d7f-57e6-8b76-b3ee2a278f56
Feed Name: cybersecurityNews.com
**MoonPeak (XenoRAT variant) LNK-based campaign targeting South Korean investors and crypto traders:** A malicious campaign observed since January 2026 uses deceptive LNK shortcuts that display XOR-encoded PDF decoys while executing obfuscated PowerShell/VBScript to perform environment checks, download additional GZIP-compressed payloads from GitHub (Living Off Trusted Sites), load payloads into memory, establish persistence via scheduled tasks, and connect to a C2 at 27.102.137.88:443; analysts link the activity to DPRK-affiliated actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
