MoonPeak is a Windows remote access trojan derived from the open-source XenoRAT .NET codebase and associated with North Korea-linked intrusion activity, particularly clusters tracked as Kimsuky or Velvet Chollima. It has been observed as the terminal payload in multi-stage infection chains that rely on social engineering, commonly using malicious shortcut files that present decoy documents while covertly launching obfuscated PowerShell. Reported campaigns have targeted South Korean users and organizations, including the gaming sector, as well as financially themed victims such as cryptocurrency traders.
Observed MoonPeak delivery chains use layered evasion and staging. Early stages perform anti-analysis checks for virtualization and security tools, gather host information, create randomized temporary artifacts, and establish persistence through Windows scheduled tasks. Subsequent stages retrieve obfuscated payloads from trusted web platforms such as GitHub or GitLab, sometimes using compression, header manipulation, or dynamic code decryption to hinder analysis. MoonPeak samples have been described as heavily obfuscated and anti-tamper protected.
MoonPeak’s role within broader campaigns is consistent with remote access and post-compromise control. Reported operations using MoonPeak or its surrounding toolchain have included host profiling, command-and-control communications over asynchronous sockets, additional payload retrieval, and durable persistence. In some financially motivated campaigns attributed to DPRK operators, MoonPeak has appeared alongside modules for reconnaissance, keylogging, browser credential theft, and cryptocurrency wallet theft, indicating its use as part of a larger monetization-focused intrusion ecosystem rather than as a standalone stealer.
The malware has been linked to DPRK operators through infrastructure and tradecraft overlaps, including prior GitHub-based XenoRAT activity, lure themes, and recurring family characteristics such as shared mutex usage. MoonPeak represents an evolution of XenoRAT with enhanced stealth and operational customization for targeted espionage and financially motivated intrusions on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The terminal payload is MoonPeak, a customised variant of the open-source XenoRAT codebase (.NET), persisted via Windows scheduled tasks.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware creates randomized temporary folders and files to evade file-based detection, then establishes persistence through scheduled task creation using WScript.exe.
The malware creates randomized temporary folders and files to evade file-based detection, then establishes persistence through scheduled task creation using WScript.exe.
Annotations ID Technique Tactic T1543 Create or Modify System Process Persistence
The following analytic detects a registry modification that allows the 'Consent Admin' to perform operations requiring elevation without user consent or credentials... This activity is significant as it indicates a potential privilege escalation attempt... Annotations ID Technique Tactic T1548 Abuse Elevation Control Mechanism Defense Evasion
The downloaded file is obfuscated through GZIP compression and header manipulation... This executable is MoonPeak malware, heavily obfuscated using ConfuserEx ... encrypts strings and code to defeat static analysis.
When users open the LNK file, two actions occur simultaneously: a decoy PDF document is displayed to maintain the illusion of a legitimate file, while an obfuscated PowerShell script executes silently
The initial PowerShell script communicates with the attacker’s command-and-control infrastructure ... transmitting system information including hostname, OS version, and process lists
The initial PowerShell script communicates with the attacker’s command-and-control infrastructure at “hxxp://mid[.]great-site[.]net,” transmitting system information including hostname, OS version, and process lists via POST requests to “/maith.php.”
The same GitHub repositories are used to store additional modules and commands, allowing operators to maintain persistent control over compromised systems while blending into trusted platforms.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage malware infection ultimately loads MoonPeak, described as a XenoRAT-based variant. The chain uses a disguised LNK lure, PowerShell scripts for environment checks and system information collection, creates aes.js at runtime to obtain cookies for C2 communication, establishes persistence via Task Scheduler, downloads and executes additional payloads, and communicates with its C2 over asynchronous sockets.
MoonPeak is the primary malware discussed in an infection case analysis targeting the gaming industry.
Associated Analytic Story ... RedLine Stealer PlugX MoonPeak WhisperGate
A variant of Xeno RAT delivered using GitHub as command-and-control infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.