logo

Constantly Evolving MoonPeak RAT Linked to North Korean Spying

ID: 0fd4a6df-e19f-5f05-9480-01e908a5c9f6

STIX ID: report--0fd4a6df-e19f-5f05-9480-01e908a5c9f6

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-08-23

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Cisco Talos researchers identified MoonPeak, a continually evolving variant of the open-source XenoRAT trojan likely used by a North Korean-linked activity cluster (UAT-5394) with ties to Kimsuky. MoonPeak retains core XenoRAT functions (keylogging, UAC bypass, HVNC) but includes deliberate namespace changes, asynchronous state-machine execution and other obfuscations; the actor also shifted payload hosting from public cloud to privately controlled infrastructure and appears to test and tailor implants to specific C2 servers to hinder detection and attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.