Threat Actors Exploit LNK Files to Deploy MoonPeak Malware on Windows Systems
ID: 63549d9c-19cc-594b-9c10-8f117c4e82d7
STIX ID: report--63549d9c-19cc-594b-9c10-8f117c4e82d7
Feed Name: GBHackers
A sophisticated, three-stage malware campaign targeting Windows users in South Korea uses crafted LNK shortcut files to show decoy PDFs while executing obfuscated PowerShell that performs reconnaissance, anti-analysis checks, persistence via scheduled tasks, and downloads an obfuscated .NET payload (MoonPeak/XenoRAT) hosted on GitHub; the report includes C2 details, file hashes, and attribution indicators pointing to DPRK-linked operators and recommends monitoring LNK execution, restricting PowerShell, and EDR detection of scheduled task creation and unusual GitHub access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
