logo

Evasive Memory-Only Malware PEAKLIGHT Uses Pirated Movies To Deliver Payloads

ID: 60cc6103-de70-53d9-b960-f19d5ad4765d

STIX ID: report--60cc6103-de70-53d9-b960-f19d5ad4765d

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2024-08-22

Date Updated: 2026-04-23

Author: Alan J

...
...

PEAKLIGHT is a stealthy, memory-only dropper distributed through malicious ZIPs posing as pirated movies: LNK files trigger PowerShell which fetches an in-memory JavaScript dropper that decodes and executes PEAKLIGHT, which in turn downloads additional payloads (including LUMMAC.V2, SHADOWADDER, and CRYPTBOT) from CDNs. Researchers observed multiple PEAKLIGHT variants that differ in target directories and execution logic; recommended defenses include scanning for IOCs and YARA rules, updating security software, and avoiding pirated content.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.