216.73.217.22

Malware MoonPeak Executed via LNK Files

· Published 26/01/2026 14:28 · Modified 26/01/2026 18:03

Export JSON

Essential information

Published
26/01/2026 14:28
Modified
26/01/2026 18:03
Tags
2026-01-26 confuserex github korea lnk files lots moonpeak persistence powershell xenorat
Related entities
4 observables, 1 intrusion sets (apt), 12 techniques (mitre), 2 malware, 1 others

Description

In January 2026, IIJ observed malicious targeting Korean users to execute the malware, attributed to North Korean threat actors. The infection chain begins with a LNK file that runs an obfuscated script, which checks for analysis environments, creates additional scripts, and sets up . The second stage downloads and executes a payload from , which is actually the malware. is obfuscated using and communicates with a C2 server. The campaign utilizes for hosting malware, a technique known as Living Off Trusted Sites (). This attack demonstrates the ongoing threat posed by North Korean actors targeting various countries and individuals worldwide.

External references