logo

Researchers Uncover Hidden Threat: ‘PEAKLIGHT’ Memory Malware Exposed

ID: d6525c0a-a999-5cba-b575-7fc1424e20f6

STIX ID: report--d6525c0a-a999-5cba-b575-7fc1424e20f6

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2024-08-23

Date Updated: 2026-04-19

Author: Kaaviya

...
...

This report describes a malicious campaign that distributes a memory-only JavaScript dropper via LNK files in ZIPs (masquerading as movie files) which triggers a PowerShell downloader named PEAKLIGHT; PEAKLIGHT retrieves and executes multiple infostealer families (LUMMAC2, SHADOWLADDER, CRYPTBOT) hosted on CDNs, using obfuscation, living-off-the-land binaries (mshta.exe, forfiles.exe), and encrypted payloads to evade detection and persist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.