Constantly Evolving MoonPeak RAT Linked to North Korean Spying
ID: 0fd4a6df-e19f-5f05-9480-01e908a5c9f6
STIX ID: report--0fd4a6df-e19f-5f05-9480-01e908a5c9f6
Feed Name: Dark Reading
Cisco Talos researchers identified MoonPeak, a continually evolving variant of the open-source XenoRAT trojan likely used by a North Korean-linked activity cluster (UAT-5394) with ties to Kimsuky. MoonPeak retains core XenoRAT functions (keylogging, UAC bypass, HVNC) but includes deliberate namespace changes, asynchronous state-machine execution and other obfuscations; the actor also shifted payload hosting from public cloud to privately controlled infrastructure and appears to test and tailor implants to specific C2 servers to hinder detection and attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
