Cisco Talos has discovered a new remote access trojan (RAT) named MoonPeak, employed by a North Korean state-sponsored threat group designated UAT-5394. This group exhibits tactical similarities to the known actor Kimsuky, implying that UAT-5394 could either be Kimsuky itself or another North Korean cyber group utilizing similar tools. MoonPeak is a variant of the open-source Xeno RAT, which has previously been used in phishing attacks to download payloads from cloud services such as Dropbox and Google Drive. MoonPeak’s functionalities include loading plugins, managing processes, and communicating with a command-and-control (C2) server. The malware is actively being developed, with each version introducing new obfuscation techniques and modifications to its communication methods, ensuring that specific versions of MoonPeak work only with their corresponding C2 servers. The campaign has transitioned from using legitimate cloud storage to deploying its own infrastructure, including C2 servers and payload-hosting sites. These servers distribute malicious artifacts and facilitate the setup of new infrastructure, enabling the rapid spread of the campaign. The threat actors have also accessed existing servers to update their payloads and collect data from MoonPeak infections. The targets of this campaign remain unidentified. However, the rapid establishment of new infrastructure and the continuous evolution of MoonPeak indicate UAT-5394’s intent to expand its operations. This underscores the group’s commitment to enhancing its toolset and maintaining control over its malicious activities while evading detection and analysis.
Charter Communications has confirmed a cybersecurity incident impacting millions of customers following a breach allegedly conducted by the ShinyHunters extortion gang. According t...
A critical Remote Code Execution (RCE) vulnerability has been identified in Samba, the widely used open-source SMB/CIFS file-sharing software for Linux and Unix systems. The flaw c...
A sophisticated cyber-espionage campaign linked to the Iran-aligned threat group Seedworm has targeted at least nine organizations across multiple countries during early 2026. The ...