MoonPeak is a Windows remote access trojan derived from the open-source, C#/.NET-based XenoRAT codebase. Identified in 2024, it is associated with North Korean-linked activity, including operations tracked as UAT-5394 and campaigns attributed to Kimsuky. It provides remote control of compromised systems, including command execution, screen monitoring, and file theft.
MoonPeak is delivered through multi-stage infection chains using malicious Windows shortcut files and PowerShell loaders. Document-themed shortcuts display decoy material while silently initiating payload retrieval. Observed lures include financial trading guidance and game-character design documents. Other campaigns distribute MoonPeak through a counterfeit cryptocurrency trading application. Targeting includes Windows users in South Korea, the gaming industry, and cryptocurrency traders.
Delivery chains use GitHub or GitLab to stage payloads, sometimes concealing compressed .NET assemblies through misleading document formats and modified GZIP headers. Supporting scripts perform host reconnaissance and check for virtualization, debugging, and forensic tools before proceeding. Windows scheduled tasks provide persistence. Analyzed MoonPeak builds use ConfuserEx obfuscation, anti-tampering measures, and dynamic code decryption to impede analysis, and communicate with command-and-control infrastructure through asynchronous sockets. These techniques combine socially engineered execution with trusted-service abuse and layered concealment to establish persistent remote access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This build belongs to the MoonPeak/Xeno RAT toolset, the same family tied to UAT-5394 / Kimsuky.
The campaign shares infrastructure overlaps with another set of attacks that delivered a variant of Xeno RAT known as MoonPeak.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware creates randomized temporary folders and files to evade file-based detection, then establishes persistence through scheduled task creation using WScript.exe.
The malware creates randomized temporary folders and files to evade file-based detection, then establishes persistence through scheduled task creation using WScript.exe.
Annotations ID Technique Tactic T1543 Create or Modify System Process Persistence
The following analytic detects a registry modification that allows the 'Consent Admin' to perform operations requiring elevation without user consent or credentials... This activity is significant as it indicates a potential privilege escalation attempt... Annotations ID Technique Tactic T1548 Abuse Elevation Control Mechanism Defense Evasion
The downloaded file is obfuscated through GZIP compression and header manipulation... This executable is MoonPeak malware, heavily obfuscated using ConfuserEx ... encrypts strings and code to defeat static analysis.
When users open the LNK file, two actions occur simultaneously: a decoy PDF document is displayed to maintain the illusion of a legitimate file, while an obfuscated PowerShell script executes silently
The initial PowerShell script communicates with the attacker’s command-and-control infrastructure ... transmitting system information including hostname, OS version, and process lists
The initial PowerShell script communicates with the attacker’s command-and-control infrastructure at “hxxp://mid[.]great-site[.]net,” transmitting system information including hostname, OS version, and process lists via POST requests to “/maith.php.”
The same GitHub repositories are used to store additional modules and commands, allowing operators to maintain persistent control over compromised systems while blending into trusted platforms.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage malware infection ultimately loads MoonPeak, described as a XenoRAT-based variant. The chain uses a disguised LNK lure, PowerShell scripts for environment checks and system information collection, creates aes.js at runtime to obtain cookies for C2 communication, establishes persistence via Task Scheduler, downloads and executes additional payloads, and communicates with its C2 over asynchronous sockets.
MoonPeak is the primary malware discussed in an infection case analysis targeting the gaming industry.
Associated Analytic Story ... RedLine Stealer PlugX MoonPeak WhisperGate
A variant of Xeno RAT delivered using GitHub as command-and-control infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.