Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»North Korean Hackers Observed Deploying New ‘MoonPeak’ Malware Infrastructure

    North Korean Hackers Observed Deploying New ‘MoonPeak’ Malware Infrastructure

    August 21, 2024

    Researchers have uncovered a new remote access trojan (RAT) family, dubbed ‘MoonPeak,’ that is being actively developed by a North Korean threat actor cluster known as ‘UAT-5394.’ The researchers’ analysis of the threat actor’s infrastructure reveals a complex web of command-and-control (C2) servers, staging servers, and test machines used to develop and deploy the malware.

    Mapping North Korean APT UAT-5394’s Infrastructure

    Talos’ investigation has led to the discovery of numerous servers owned, operated and administered by UAT-5394. This infrastructure includes C2 servers, payload-hosting sites, and virtual machines used to test their MoonPeak implants before distribution.

    The researchers observed a distinct shift in the actor’s tactics in June 2024, as they moved from hosting malicious payloads on legitimate cloud storage providers to systems and servers they now owned and controlled. This was likely done to preserve their infections from potential shutdowns by cloud service providers.

    Source: Talos

    The campaign involved the use of multiple C2 servers, payload-hosting sites, and test virtual machines to test MoonPeak implants before distributing them to potential targets. The threat actors have also been observed accessing their infrastructure from VPN nodes, highlighting their ability to adapt and evolve.

    Another key server in UAT-5394’s infrastructure was 167.88.173.173, a high-flux server that had been observed changing operating systems and web servers multiple times in a span of less than two months. While this server was initially linked to the Gamaredon APT, a threat group allegedly associated with the Russian FSB, the researcher’s analysis found a window of time in late June and early July 2024 where the researchers assess with high confidence that the IP was under UAT-5394’s control.

    During this period, the server was running Windows Server 2022 and was used by UAT-5394 to compile MoonPeak v2 malware samples pointing to its port 9966 as the C2 server. The researchers also observed two other IP addresses, 45.87.153.79 and 45.95.11.52, accessing this server over ports 9936 and 9966 – the same C2 ports used by MoonPeak malware.

    The investigation also revealed that 167.88.173.173 resolved to and hosted an SSL certificate for the malicious domain pumaria.store, which was later found to resolve to 104.194.152.251 on July 11, 2024. On the same day, one of UAT-5394’s test machines, 80.71.157.55, communicated with 104.194.152.251 over port 443, indicating that this system was being used to test MoonPeak infections.

    Further analysis of 104.194.152.251 showed that it resolved to other domains attributed to UAT-5394, such as yoiroyse.store, and was used to host MoonPeak malware and set up a new C2 server at 91.194.161.109.

    Testing And Evolving MoonPeak

    The researchers observed the use of several virtual machines on the servers 45.87.153.79, 45.95.11.52, and 80.71.157.55, used by UAT-5394 to test MoonPeak infections over various C2 ports since at least July 2, 2024.

    The researchers noted that the test timings over these ports matched the compilation times of the various MoonPeak samples they had noted, further observing an evolution in the malware and its corresponding C2 components, with each new increment differing from the previous one in terms of evasion techniques and infrastructure changes.

    This constant evolution suggests that the threat actors are actively developing and refining MoonPeak to evade detection. The threat actors have been observed deploying their implant variants several times on their test machines, demonstrating capability as well as the resources for adaptability.

    Potential indicators of compromise (IOCs) from MoonPeak’s campaigns and attack operations were shared over GitHub.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleResearchers Uncover Backdoor in Millions of Chinese RFID Smart Cards
    Next Article The AI Fix #12: AI made from human brain cells, and is there life after death?

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 17, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-40906 – MongoDB BSON Serialization BSON::XS Multiple Vulnerabilities

    May 17, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    Balatro shuffles onto Xbox Game Pass with a surprise launch, bringing 2024’s best indie game to the service

    News & Updates

    Advancing Time Series Forecasting: The Impact of Bi-Mamba4TS’s Bidirectional State Space Modeling on Long-Term Predictive Accuracy

    Development

    CVE-2025-28201 – Victure RX1800 Root RCE

    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-4109 – PHPGurukul Pre-School Enrollment System SQL Injection Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    5 essential Linux terms every new user needs to know

    August 19, 2024

    If you’re considering trying the open-source OS but are put off by all the terminology,…

    Researchers from Fudan University Introduce Lorsa: A Sparse Attention Mechanism That Recovers Atomic Attention Units Hidden in Transformer Superposition

    May 7, 2025

    Kinsing Hacker Group Exploits More Flaws to Expand Botnet for Cryptojacking

    May 17, 2024

    Workload Automation vs Service Orchestration: What’s the Difference?

    July 5, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.