logo

LNKファイルを介して実行されるマルウェアMoonPeak

ID: 8ea85dfd-4b69-593e-bfe5-86a187c890fd

STIX ID: report--8ea85dfd-4b69-593e-bfe5-86a187c890fd

Feed Name: IIJ Security Diary

Threat Score
85/100

Date Published: 2026-01-22

Date Updated: 2026-07-15

Author: Naoki Takayama

...
...

Executive summary: This report analyzes a January 2026 campaign attributed to DPRK-linked actors that used a malicious LNK (decoy PDF) to execute obfuscated PowerShell and VBScript, fetch a GitHub-hosted payload (octobor.docx → Stella.exe), and load MoonPeak (a ConfuserEx-obfuscated XenoRAT variant) in memory; it documents detection evasion, persistence via scheduled tasks, C2 (27.102.137.88:443), IoCs (file hashes, email, URLs), and takedown actions for the malicious GitHub repository.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.