Researchers Uncover Hidden Threat: ‘PEAKLIGHT’ Memory Malware Exposed
ID: d6525c0a-a999-5cba-b575-7fc1424e20f6
STIX ID: report--d6525c0a-a999-5cba-b575-7fc1424e20f6
Feed Name: Cyber Press
Threat Score
This report describes a malicious campaign that distributes a memory-only JavaScript dropper via LNK files in ZIPs (masquerading as movie files) which triggers a PowerShell downloader named PEAKLIGHT; PEAKLIGHT retrieves and executes multiple infostealer families (LUMMAC2, SHADOWLADDER, CRYPTBOT) hosted on CDNs, using obfuscation, living-off-the-land binaries (mshta.exe, forfiles.exe), and encrypted payloads to evade detection and persist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
