Hauri reported a multi-stage MoonPeak intrusion targeting the gaming industry that began with a malicious Windows shortcut (.LNK) file disguised as a game character design document. When opened, the file launched a PowerShell-based infection chain that checked for analysis environments, gathered host information, and created aes.js at runtime to steal browser cookies, which were then used in command-and-control communications. The campaign used social engineering tailored to game-development workflows, indicating deliberate targeting of gaming-sector personnel.
The malware established persistence through Windows Task Scheduler, downloaded additional payloads, and restored a later-stage component from GZIP data masquerading as an RTF file. Hauri identified the final payload as MoonPeak, a variant based on XenoRAT, citing its asynchronous socket communications with its C2 server and reuse of a mutex string previously observed in MoonPeak cases. A related social media post amplified the report and highlighted the same core elements: MoonPeak, XenoRAT, and malicious LNK delivery.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Hauri released a report describing a multi-stage intrusion chain targeting the gaming industry, beginning with a malicious LNK file and culminating in deployment of MoonPeak, a XenoRAT-based payload. The analysis links the activity to the MoonPeak family through asynchronous C2 socket communication and reuse of a mutex seen in prior MoonPeak cases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.