LNKファイルを介して実行されるマルウェアMoonPeak
ID: 8ea85dfd-4b69-593e-bfe5-86a187c890fd
STIX ID: report--8ea85dfd-4b69-593e-bfe5-86a187c890fd
Feed Name: IIJ Security Diary
Executive summary: This report analyzes a January 2026 campaign attributed to DPRK-linked actors that used a malicious LNK (decoy PDF) to execute obfuscated PowerShell and VBScript, fetch a GitHub-hosted payload (octobor.docx → Stella.exe), and load MoonPeak (a ConfuserEx-obfuscated XenoRAT variant) in memory; it documents detection evasion, persistence via scheduled tasks, C2 (27.102.137.88:443), IoCs (file hashes, email, URLs), and takedown actions for the malicious GitHub repository.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
