MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$76,859.00-1.98%
  • ethereumEthereum(ETH)$2,289.66-3.39%
  • tetherTether(USDT)$1.00-0.03%
  • rippleXRP(XRP)$1.39-2.78%
  • binancecoinBNB(BNB)$623.07-1.89%
  • usd-coinUSDC(USDC)$1.000.01%
  • solanaSolana(SOL)$84.45-2.94%
  • tronTRON(TRX)$0.3258310.50%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.031.51%
  • dogecoinDogecoin(DOGE)$0.097983-1.36%
Trading Strategies

Threat Actors Weaponizes LNK File to Deploy MoonPeak Malware Attacking Windows Systems

Last updated: January 24, 2026 1:50 am
Published: 3 months ago
Share

A new malware campaign targeting Windows users has emerged, using deceptive LNK shortcut files to distribute MoonPeak, a dangerous remote access trojan.

This malware, which appears to be a variant of XenoRAT, has been linked to threat actors affiliated with North Korea.

The attack primarily targets South Korean investors and cryptocurrency traders through weaponized files disguised as legitimate PDF documents related to trading strategies.

When victims open the malicious LNK file, it triggers a sophisticated infection chain that deploys the malware while displaying a decoy PDF to avoid suspicion.

The campaign was first detected in January 2026, with LNK files containing Korean filenames suggesting investment-related content.

These files embed an XOR-encoded PDF that opens normally when clicked, making the attack appear harmless to unsuspecting users.

Behind the scenes, however, an obfuscated PowerShell script executes silently in a hidden window.

This script initiates multiple stages of payload delivery, establishing persistence on the infected system and communicating with remote servers controlled by the attackers.

IIJ Security Diary analysts identified this threat through detailed malware analysis, uncovering the complete infection flow that had not been fully documented in earlier reports.

The researchers traced the attack infrastructure to GitHub repositories used for hosting malicious payloads, demonstrating the threat actors’ use of legitimate platforms to evade detection.

This technique, known as Living Off Trusted Sites (LOTS), allows attackers to bypass security measures that typically block suspicious domains.

Multi-Stage Infection Mechanism and Evasion Tactics

The MoonPeak infection process operates through three distinct stages, each designed to evade security analysis and establish persistent access.

In the first stage, the LNK file checks for security tools and virtual environments by scanning for specific running processes such as IDA Pro, Wireshark, OllyDbg, and various sandbox indicators.

If any analysis tools are detected, the script immediately terminates to prevent researchers from studying its behavior. This anti-analysis technique ensures the malware only executes on genuine victim systems.

Once the environment check passes, the PowerShell script creates randomly named folders and files in the temporary directory, downloading additional scripts from remote servers.

A scheduled task is then created to ensure the malware runs automatically, even after system reboots.

The second stage involves retrieving a GZIP-compressed payload from a GitHub repository, which is decompressed and loaded directly into memory without touching the disk.

The final stage deploys MoonPeak itself, obfuscated using ConfuserEx to resist decompilation and analysis. The malware connects to its command-and-control server at 27.102.137[.]88:443, enabling attackers to remotely control infected machines.

Follow us on Google News, LinkedIn, and X to Get More Instant Updates, Set CSN as a Preferred Source in Google.

Read more on Cyber Security News

This news is powered by Cyber Security News Cyber Security News

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Canadian Inflation Holds Steady Despite Minor Hiccups
DiversiFi Unveils Revolutionary Deflationary Crypto Token Empowering Traders with AI-Driven Strategies
BingX introduces BingX TradFi, expanding access to global financial markets
SHIB Price Analysis: Neutral RSI Signals Potential Breakout Despite 6% Daily Drop
The Complete Guide to Prop Trading: How to Start Trading with Other People’s Money

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article PwC Report: Institutional Crypto Adoption Reaches Irreversible Stage
Next Article Renaissance, Schonfeld, and Engineers Gate stung in a shaky start for quants in 2026
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d