MoonPeak is a Windows remote access trojan in the XenoRAT family, generally described as a customized or variant build of the open-source .NET XenoRAT codebase. It has been linked at high confidence to DPRK-aligned activity, particularly Kimsuky and related tracking clusters such as UAT-5394, and has been used in campaigns targeting South Korean users as well as cryptocurrency-focused victims. Reported targeting has included South Korean organizations and users, the gaming sector, and financially themed operations aimed at cryptocurrency traders.
Observed MoonPeak intrusion chains commonly rely on social engineering and script-based staging. Document-themed or finance-themed lures have been delivered through malicious Windows shortcut files that display decoy content while covertly launching obfuscated PowerShell. In other campaigns, a trojanized cryptocurrency trading application was used to stage the malware. Delivery infrastructure has included trusted developer or content platforms such as GitHub and GitLab, which were used to host or retrieve later-stage payloads.
The malware’s staging logic has shown strong emphasis on defense evasion. Reported chains perform anti-analysis checks for virtualization and security tooling, use randomized temporary artifacts, and in some cases restore payloads from manipulated GZIP data or load .NET assemblies reflectively in memory. MoonPeak samples have also been described as heavily obfuscated and capable of dynamic code decryption during execution.
Persistence has repeatedly been established through Windows scheduled tasks. Associated infection chains also perform host profiling and reconnaissance before deploying the final RAT. In some observed cases, intermediate scripts collected system information and used browser-derived data such as cookies during command-and-control communications.
As a XenoRAT-derived implant, MoonPeak is assessed to provide remote access and post-compromise control over infected Windows systems. Reporting directly associates MoonPeak campaigns with asynchronous socket-based command-and-control and with broader Kimsuky tradecraft involving staged payload retrieval, host reconnaissance, and follow-on malicious activity including credential and wallet theft in cryptocurrency-focused operations. The malware is best understood as a DPRK-linked RAT used in multi-stage intrusions that blend espionage-oriented access with financially motivated targeting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This build belongs to the MoonPeak/Xeno RAT toolset, the same family tied to UAT-5394 / Kimsuky.
This build belongs to the MoonPeak/Xeno RAT toolset, the same family tied to UAT-5394 / Kimsuky.
The campaign shares infrastructure overlaps with another set of attacks that delivered a variant of Xeno RAT known as MoonPeak.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware creates randomized temporary folders and files to evade file-based detection, then establishes persistence through scheduled task creation using WScript.exe.
The malware creates randomized temporary folders and files to evade file-based detection, then establishes persistence through scheduled task creation using WScript.exe.
Annotations ID Technique Tactic T1543 Create or Modify System Process Persistence
The following analytic detects a registry modification that allows the 'Consent Admin' to perform operations requiring elevation without user consent or credentials... This activity is significant as it indicates a potential privilege escalation attempt... Annotations ID Technique Tactic T1548 Abuse Elevation Control Mechanism Defense Evasion
The downloaded file is obfuscated through GZIP compression and header manipulation... This executable is MoonPeak malware, heavily obfuscated using ConfuserEx ... encrypts strings and code to defeat static analysis.
When users open the LNK file, two actions occur simultaneously: a decoy PDF document is displayed to maintain the illusion of a legitimate file, while an obfuscated PowerShell script executes silently
The initial PowerShell script communicates with the attacker’s command-and-control infrastructure ... transmitting system information including hostname, OS version, and process lists
The initial PowerShell script communicates with the attacker’s command-and-control infrastructure at “hxxp://mid[.]great-site[.]net,” transmitting system information including hostname, OS version, and process lists via POST requests to “/maith.php.”
The same GitHub repositories are used to store additional modules and commands, allowing operators to maintain persistent control over compromised systems while blending into trusted platforms.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage malware infection ultimately loads MoonPeak, described as a XenoRAT-based variant. The chain uses a disguised LNK lure, PowerShell scripts for environment checks and system information collection, creates aes.js at runtime to obtain cookies for C2 communication, establishes persistence via Task Scheduler, downloads and executes additional payloads, and communicates with its C2 over asynchronous sockets.
MoonPeak is the primary malware discussed in an infection case analysis targeting the gaming industry.
Associated Analytic Story ... RedLine Stealer PlugX MoonPeak WhisperGate
A variant of Xeno RAT delivered using GitHub as command-and-control infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.