Skip to content

MoonPeak

MoonPeak is a Windows remote access trojan derived from the open-source XenoRAT .NET codebase and associated with North Korea-linked intrusion activity, particularly clusters tracked as Kimsuky or Velvet Chollima.

Profile source: Mallory opens in a new tab

MoonPeak

Family profile

MoonPeak is a Windows remote access trojan derived from the open-source XenoRAT .NET codebase and associated with North Korea-linked intrusion activity, particularly clusters tracked as Kimsuky or Velvet Chollima. It has been observed as the terminal payload in multi-stage infection chains that rely on social engineering, commonly using malicious shortcut files that present decoy documents while covertly launching obfuscated PowerShell. Reported campaigns have targeted South Korean users and organizations, including the gaming sector, as well as financially themed victims such as cryptocurrency traders.

Observed MoonPeak delivery chains use layered evasion and staging. Early stages perform anti-analysis checks for virtualization and security tools, gather host information, create randomized temporary artifacts, and establish persistence through Windows scheduled tasks. Subsequent stages retrieve obfuscated payloads from trusted web platforms such as GitHub or GitLab, sometimes using compression, header manipulation, or dynamic code decryption to hinder analysis. MoonPeak samples have been described as heavily obfuscated and anti-tamper protected.

MoonPeak’s role within broader campaigns is consistent with remote access and post-compromise control. Reported operations using MoonPeak or its surrounding toolchain have included host profiling, command-and-control communications over asynchronous sockets, additional payload retrieval, and durable persistence. In some financially motivated campaigns attributed to DPRK operators, MoonPeak has appeared alongside modules for reconnaissance, keylogging, browser credential theft, and cryptocurrency wallet theft, indicating its use as part of a larger monetization-focused intrusion ecosystem rather than as a standalone stealer.

The malware has been linked to DPRK operators through infrastructure and tradecraft overlaps, including prior GitHub-based XenoRAT activity, lure themes, and recurring family characteristics such as shared mutex usage. MoonPeak represents an evolution of XenoRAT with enhanced stealth and operational customization for targeted espionage and financially motivated intrusions on Windows systems.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 13, 2026
Last activity
Aug 13, 2026
Feed role
C2 / Distribution
Host form
2 IP / 0 hostnames

Leading locations

  • FR1
  • US1

Leading providers

  • AS56971 Cloud1
  • HostPapa1

Infrastructure traits

  • Hosting 2

Reported operators

Threat actors

1 named in public reporting
Kimsuky

The terminal payload is MoonPeak, a customised variant of the open-source XenoRAT codebase (.NET), persisted via Windows scheduled tasks.

MITRE ATT&CK

MoonPeak in ATT&CK

33 distinct techniques

Reporting

Research mentioning MoonPeak

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.