North Korea S Cyber Threat Evolves With Moonpeak Malware
In their report, published yesterday, the researchers state that MoonPeak is based on the publicly available source code for XenoRAT, which was released on GitHub around October 2023. Although MoonPeak retains many of the original XenoRAT’s functionalities, Cisco Talos’ analysis has identified consistent changes across its variants, indicating that the threat actors are independently modifying and evolving the code beyond the open-source version. While MoonPeak shares some similarities with malware used by a known North Korean group called “Kimsuky,” Cisco Talos states they don’t have enough evidence to confirm a direct link between them....