PEAKLIGHT: Decoding the Stealthy Memory-Only Malware
ID: 31092961-5d17-5b60-87ee-f7f8449bb98e
STIX ID: report--31092961-5d17-5b60-87ee-f7f8449bb98e
Feed Name: Google Cloud Threat Intelligence
Threat Score
A Mandiant YARA rule for detecting the PEAKLIGHT PowerShell downloader. The rule matches on multiple PowerShell patterns (file write via [IO.File]::WriteAllBytes, Expand-Archive usage, ZIP handling, TLS12 enforcement, and network download calls) and triggers when at least four specific strings are found in a file under 10KB. This indicates detection logic for an obfuscated downloader that retrieves and extracts payloads from a CDN.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
