Last seven days
- First activity
- Aug 13, 2026
- Last activity
- Aug 13, 2026
- Feed role
- C2 / Distribution
- Host form
- 2 IP / 0 hostnames
MoonPeak is a Windows remote access trojan derived from the open-source XenoRAT .NET codebase and associated with North Korea-linked intrusion activity, particularly clusters tracked as Kimsuky or Velvet Chollima.
Profile source: Mallory opens in a new tabMoonPeak
MoonPeak is a Windows remote access trojan derived from the open-source XenoRAT .NET codebase and associated with North Korea-linked intrusion activity, particularly clusters tracked as Kimsuky or Velvet Chollima. It has been observed as the terminal payload in multi-stage infection chains that rely on social engineering, commonly using malicious shortcut files that present decoy documents while covertly launching obfuscated PowerShell. Reported campaigns have targeted South Korean users and organizations, including the gaming sector, as well as financially themed victims such as cryptocurrency traders.
Observed MoonPeak delivery chains use layered evasion and staging. Early stages perform anti-analysis checks for virtualization and security tools, gather host information, create randomized temporary artifacts, and establish persistence through Windows scheduled tasks. Subsequent stages retrieve obfuscated payloads from trusted web platforms such as GitHub or GitLab, sometimes using compression, header manipulation, or dynamic code decryption to hinder analysis. MoonPeak samples have been described as heavily obfuscated and anti-tamper protected.
MoonPeak’s role within broader campaigns is consistent with remote access and post-compromise control. Reported operations using MoonPeak or its surrounding toolchain have included host profiling, command-and-control communications over asynchronous sockets, additional payload retrieval, and durable persistence. In some financially motivated campaigns attributed to DPRK operators, MoonPeak has appeared alongside modules for reconnaissance, keylogging, browser credential theft, and cryptocurrency wallet theft, indicating its use as part of a larger monetization-focused intrusion ecosystem rather than as a standalone stealer.
The malware has been linked to DPRK operators through infrastructure and tradecraft overlaps, including prior GitHub-based XenoRAT activity, lure themes, and recurring family characteristics such as shared mutex usage. MoonPeak represents an evolution of XenoRAT with enhanced stealth and operational customization for targeted espionage and financially motivated intrusions on Windows systems.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
The terminal payload is MoonPeak, a customised variant of the open-source XenoRAT codebase (.NET), persisted via Windows scheduled tasks.
MITRE ATT&CK
Reporting
Hauri reported a multi-stage MoonPeak intrusion targeting the gaming industry that began with a malicious Windows shortcut (.LNK) file disguised as a game character design document. When opened, the file launched a PowerShell-based infection chain that checked for analysis environments, gathered host information, and created aes.js at runtime to steal browser cookies, which were then used in command-and-control communications. The campaign used social engineering tailored to game-development workflows, indicating deliberate targeting of gaming-sector personnel. The malware established persistence through Windows Task Scheduler, downloaded additional payloads, and restored a later-stage component from GZIP data masquerading as an RTF file. Hauri identified the final payload as MoonPeak, a variant based on XenoRAT, citing its asynchronous socket communications with its C2 server and reuse of a mutex string previously observed in MoonPeak cases. A related social media post amplified the report and highlighted the same core elements: MoonPeak, XenoRAT, and malicious LNK delivery.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.