LNKファイルを介して実行されるマルウェアMoonPeak
2026-01-22 • IIJSECT • MoonPeak Malware Executed Through LNK Files •
https://sect.iij.ad.jp/blog/2026/01/dprk-moonpeak-executed-via-malicious-lnk-file/
IIJ observed a malicious LNK file likely used against Korean users that executed MoonPeak, a XenoRAT variant attributed in the source to DPRK-linked activity. The lure opened a Korean investment-themed decoy PDF while hidden PowerShell checked for analysis tools, created a scheduled task for persistence, and sent host, domain, OS, and process data to mid.great-site.net. A second-stage script retrieved files from the GitHub repository macsim-gun/FinalDocu, converted octobor.docx into GZIP data, and loaded the ConfuserEx-obfuscated MoonPeak payload Stella.exe in memory. The activity shows continued use of trusted hosting such as GitHub and infrastructure patterns overlapping previously reported MoonPeak campaigns.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | aaac6eadac6c325bfc69b561d75f7cf… | 2026-01-22 | 2026-01-22 |
| HASH | d8e96e777de3234e0771e6c53b7c09a… | 2026-01-22 | 2026-01-22 |
| HASH | 1553bfac012b20a39822c5f2ef3a7bd… | 2026-01-22 | 2026-01-22 |
| HASH | 8de36cb635eb87c1aa0e8219f1d8bf2… | 2026-01-22 | 2026-01-22 |
| URL | http://mid.great-site.net/aes.js | 2026-01-22 | 2026-01-22 |
| URL | http://mid.great-site.net/realz… | 2026-01-22 | 2026-01-22 |
| URL | http://mid.great-site.net/maith… | 2026-01-22 | 2026-01-22 |
| DOMAIN | mid.great-site.net | 2026-01-22 | 2026-01-22 |
| IPv4 | 27.102.137.88 | 2026-01-22 | 2026-01-22 |