logo

PEAKLIGHT: Decoding the Stealthy Memory-Only Malware

ID: 31092961-5d17-5b60-87ee-f7f8449bb98e

STIX ID: report--31092961-5d17-5b60-87ee-f7f8449bb98e

Feed Name: Google Cloud Threat Intelligence

Threat Score
55/100

Date Published: 2024-08-22

Date Updated: 2026-04-27

Author: Mandiant

...
...

A Mandiant YARA rule for detecting the PEAKLIGHT PowerShell downloader. The rule matches on multiple PowerShell patterns (file write via [IO.File]::WriteAllBytes, Expand-Archive usage, ZIP handling, TLS12 enforcement, and network download calls) and triggers when at least four specific strings are found in a file under 10KB. This indicates detection logic for an obfuscated downloader that retrieves and extracts payloads from a CDN.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.