LNKファイルを介して実行されるマルウェアMoonPeak

2026-01-22 IIJSECT MoonPeak Malware Executed Through LNK Files

https://sect.iij.ad.jp/blog/2026/01/dprk-moonpeak-executed-via-malicious-lnk-file/

Thumbnail for LNKファイルを介して実行されるマルウェアMoonPeak

IIJ observed a malicious LNK file likely used against Korean users that executed MoonPeak, a XenoRAT variant attributed in the source to DPRK-linked activity. The lure opened a Korean investment-themed decoy PDF while hidden PowerShell checked for analysis tools, created a scheduled task for persistence, and sent host, domain, OS, and process data to mid.great-site.net. A second-stage script retrieved files from the GitHub repository macsim-gun/FinalDocu, converted octobor.docx into GZIP data, and loaded the ConfuserEx-obfuscated MoonPeak payload Stella.exe in memory. The activity shows continued use of trusted hosting such as GitHub and infrastructure patterns overlapping previously reported MoonPeak campaigns.

Indicators of Compromise

Type Value First Seen Last Seen
HASH aaac6eadac6c325bfc69b561d75f7cf… 2026-01-22 2026-01-22
HASH d8e96e777de3234e0771e6c53b7c09a… 2026-01-22 2026-01-22
HASH 1553bfac012b20a39822c5f2ef3a7bd… 2026-01-22 2026-01-22
HASH 8de36cb635eb87c1aa0e8219f1d8bf2… 2026-01-22 2026-01-22
URL http://mid.great-site.net/aes.js 2026-01-22 2026-01-22
URL http://mid.great-site.net/realz… 2026-01-22 2026-01-22
URL http://mid.great-site.net/maith… 2026-01-22 2026-01-22
DOMAIN mid.great-site.net 2026-01-22 2026-01-22
IPv4 27.102.137.88 2026-01-22 2026-01-22

Related Reports

« Back