Evasive Memory-Only Malware PEAKLIGHT Uses Pirated Movies To Deliver Payloads
ID: 60cc6103-de70-53d9-b960-f19d5ad4765d
STIX ID: report--60cc6103-de70-53d9-b960-f19d5ad4765d
Feed Name: The Cyber Express
PEAKLIGHT is a stealthy, memory-only dropper distributed through malicious ZIPs posing as pirated movies: LNK files trigger PowerShell which fetches an in-memory JavaScript dropper that decodes and executes PEAKLIGHT, which in turn downloads additional payloads (including LUMMAC.V2, SHADOWADDER, and CRYPTBOT) from CDNs. Researchers observed multiple PEAKLIGHT variants that differ in target directories and execution logic; recommended defenses include scanning for IOCs and YARA rules, updating security software, and avoiding pirated content.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
