logo

Threat Actors Exploit LNK Files to Deploy MoonPeak Malware on Windows Systems

ID: 63549d9c-19cc-594b-9c10-8f117c4e82d7

STIX ID: report--63549d9c-19cc-594b-9c10-8f117c4e82d7

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-01-23

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A sophisticated, three-stage malware campaign targeting Windows users in South Korea uses crafted LNK shortcut files to show decoy PDFs while executing obfuscated PowerShell that performs reconnaissance, anti-analysis checks, persistence via scheduled tasks, and downloads an obfuscated .NET payload (MoonPeak/XenoRAT) hosted on GitHub; the report includes C2 details, file hashes, and attribution indicators pointing to DPRK-linked operators and recommends monitoring LNK execution, restricting PowerShell, and EDR detection of scheduled task creation and unusual GitHub access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.