mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -37,6 +37,7 @@ tags:
|
||||
- Ransomware
|
||||
- Windows Registry Abuse
|
||||
- Azorult
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -74,6 +74,7 @@ tags:
|
||||
- Snake Keylogger
|
||||
- AcidPour
|
||||
- Handala Wiper
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 40
|
||||
|
||||
@@ -37,6 +37,7 @@ tags:
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
- IcedID
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 50
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
- IcedID
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 50
|
||||
|
||||
@@ -32,6 +32,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Malicious PowerShell
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 100
|
||||
|
||||
@@ -40,6 +40,7 @@ tags:
|
||||
- Prestige Ransomware
|
||||
- Malicious PowerShell
|
||||
- Data Destruction
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 70
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
- LockBit Ransomware
|
||||
- Malicious PowerShell
|
||||
- Data Destruction
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 75
|
||||
|
||||
@@ -76,6 +76,7 @@ tags:
|
||||
- BlackByte Ransomware
|
||||
- CISA AA23-347A
|
||||
- Snake Keylogger
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 95
|
||||
impact: 80
|
||||
|
||||
@@ -63,6 +63,7 @@ tags:
|
||||
- CISA AA23-347A
|
||||
- Phemedrone Stealer
|
||||
- ShrinkLocker
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 70
|
||||
|
||||
@@ -48,6 +48,7 @@ tags:
|
||||
analytic_story:
|
||||
- Windows Defense Evasion Tactics
|
||||
- Windows Registry Abuse
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 70
|
||||
|
||||
@@ -79,6 +79,7 @@ tags:
|
||||
- Data Destruction
|
||||
- Phemedrone Stealer
|
||||
- Handala Wiper
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 70
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
- Living Off The Land
|
||||
- DarkCrystal RAT
|
||||
- CISA AA23-347A
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 70
|
||||
|
||||
@@ -36,6 +36,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Snake Keylogger
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
+1
@@ -35,6 +35,7 @@ tags:
|
||||
- Amadey
|
||||
- RedLine Stealer
|
||||
- Phemedrone Stealer
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
+1
@@ -36,6 +36,7 @@ tags:
|
||||
- DarkGate Malware
|
||||
- Phemedrone Stealer
|
||||
- Snake Keylogger
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
+1
@@ -37,6 +37,7 @@ tags:
|
||||
- DarkGate Malware
|
||||
- Phemedrone Stealer
|
||||
- Snake Keylogger
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
- Winter Vivern
|
||||
- CISA AA23-347A
|
||||
- Scheduled Tasks
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
dataset:
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
- DarkCrystal RAT
|
||||
- NjRAT
|
||||
- DarkGate Malware
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 60
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
- Sandworm Tools
|
||||
- NjRAT
|
||||
- DarkGate Malware
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
- Windows Defense Evasion Tactics
|
||||
- Living Off The Land
|
||||
- Windows Registry Abuse
|
||||
- MoonPeak
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 70
|
||||
|
||||
@@ -0,0 +1,17 @@
|
||||
name: MoonPeak
|
||||
id: b32c2bb4-ddb0-402f-a05d-9eae0ef4007a
|
||||
version: 1
|
||||
date: '2024-08-21'
|
||||
author: Teoderick Contreras, Splunk
|
||||
description: Leverage searches that allow you to detect and investigate unusual activities linked to the MoonPeak malware, particularly focusing on command-and-control (C2) communications, data collection, file execution, and persistence mechanisms. Monitor network traffic for connections to known malicious IP addresses or domains associated with North Korean APT groups. Additionally, identify unexpected registry modifications and the presence of unauthorized binaries to uncover potential MoonPeak infections.
|
||||
narrative: The MoonPeak malware is a sophisticated cyber threat attributed to North Korean advanced persistent threat (APT) groups. This malware is designed to infiltrate targeted systems, establish persistence, and communicate with command-and-control (C2) servers, enabling remote attackers to execute malicious activities. MoonPeak often evades detection by leveraging encryption and obfuscation techniques, making it challenging for traditional security measures to identify its presence. It primarily targets government entities, critical infrastructure, and organizations of strategic interest, with the ultimate goal of espionage, data exfiltration, and disruption of operations. Its evolving tactics highlight the growing complexity of nation-state cyber operations.
|
||||
references:
|
||||
- https://blog.talosintelligence.com/moonpeak-malware-infrastructure-north-korea/
|
||||
tags:
|
||||
category:
|
||||
- Malware
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
usecase: Advanced Threat Detection
|
||||
Reference in New Issue
Block a user