Branch was auto-updated.

This commit is contained in:
Bhavin Patel
2024-08-22 17:21:04 +05:30
committed by GitHub
21 changed files with 37 additions and 0 deletions
@@ -37,6 +37,7 @@ tags:
- Ransomware
- Windows Registry Abuse
- Azorult
- MoonPeak
asset_type: Endpoint
confidence: 50
impact: 50
@@ -74,6 +74,7 @@ tags:
- Snake Keylogger
- AcidPour
- Handala Wiper
- MoonPeak
asset_type: Endpoint
confidence: 50
impact: 40
@@ -37,6 +37,7 @@ tags:
- Hermetic Wiper
- Data Destruction
- IcedID
- MoonPeak
asset_type: Endpoint
confidence: 80
impact: 50
@@ -38,6 +38,7 @@ tags:
- Hermetic Wiper
- Data Destruction
- IcedID
- MoonPeak
asset_type: Endpoint
confidence: 80
impact: 50
@@ -32,6 +32,7 @@ references:
tags:
analytic_story:
- Malicious PowerShell
- MoonPeak
asset_type: Endpoint
confidence: 80
impact: 100
@@ -40,6 +40,7 @@ tags:
- Prestige Ransomware
- Malicious PowerShell
- Data Destruction
- MoonPeak
asset_type: Endpoint
confidence: 80
impact: 70
@@ -45,6 +45,7 @@ tags:
- LockBit Ransomware
- Malicious PowerShell
- Data Destruction
- MoonPeak
asset_type: Endpoint
confidence: 80
impact: 75
@@ -76,6 +76,7 @@ tags:
- BlackByte Ransomware
- CISA AA23-347A
- Snake Keylogger
- MoonPeak
asset_type: Endpoint
confidence: 95
impact: 80
@@ -63,6 +63,7 @@ tags:
- CISA AA23-347A
- Phemedrone Stealer
- ShrinkLocker
- MoonPeak
asset_type: Endpoint
confidence: 80
impact: 70
@@ -48,6 +48,7 @@ tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Registry Abuse
- MoonPeak
asset_type: Endpoint
confidence: 90
impact: 70
@@ -79,6 +79,7 @@ tags:
- Data Destruction
- Phemedrone Stealer
- Handala Wiper
- MoonPeak
asset_type: Endpoint
confidence: 50
impact: 70
@@ -49,6 +49,7 @@ tags:
- Living Off The Land
- DarkCrystal RAT
- CISA AA23-347A
- MoonPeak
asset_type: Endpoint
confidence: 50
impact: 70
@@ -36,6 +36,7 @@ references:
tags:
analytic_story:
- Snake Keylogger
- MoonPeak
asset_type: Endpoint
confidence: 50
impact: 50
@@ -35,6 +35,7 @@ tags:
- Amadey
- RedLine Stealer
- Phemedrone Stealer
- MoonPeak
asset_type: Endpoint
confidence: 50
impact: 50
@@ -36,6 +36,7 @@ tags:
- DarkGate Malware
- Phemedrone Stealer
- Snake Keylogger
- MoonPeak
asset_type: Endpoint
confidence: 50
impact: 50
@@ -37,6 +37,7 @@ tags:
- DarkGate Malware
- Phemedrone Stealer
- Snake Keylogger
- MoonPeak
asset_type: Endpoint
confidence: 70
impact: 70
@@ -42,6 +42,7 @@ tags:
- Winter Vivern
- CISA AA23-347A
- Scheduled Tasks
- MoonPeak
asset_type: Endpoint
confidence: 70
dataset:
@@ -44,6 +44,7 @@ tags:
- DarkCrystal RAT
- NjRAT
- DarkGate Malware
- MoonPeak
asset_type: Endpoint
confidence: 50
impact: 60
@@ -44,6 +44,7 @@ tags:
- Sandworm Tools
- NjRAT
- DarkGate Malware
- MoonPeak
asset_type: Endpoint
confidence: 70
impact: 70
@@ -47,6 +47,7 @@ tags:
- Windows Defense Evasion Tactics
- Living Off The Land
- Windows Registry Abuse
- MoonPeak
asset_type: Endpoint
confidence: 90
impact: 70
+17
View File
@@ -0,0 +1,17 @@
name: MoonPeak
id: b32c2bb4-ddb0-402f-a05d-9eae0ef4007a
version: 1
date: '2024-08-21'
author: Teoderick Contreras, Splunk
description: Leverage searches that allow you to detect and investigate unusual activities linked to the MoonPeak malware, particularly focusing on command-and-control (C2) communications, data collection, file execution, and persistence mechanisms. Monitor network traffic for connections to known malicious IP addresses or domains associated with North Korean APT groups. Additionally, identify unexpected registry modifications and the presence of unauthorized binaries to uncover potential MoonPeak infections.
narrative: The MoonPeak malware is a sophisticated cyber threat attributed to North Korean advanced persistent threat (APT) groups. This malware is designed to infiltrate targeted systems, establish persistence, and communicate with command-and-control (C2) servers, enabling remote attackers to execute malicious activities. MoonPeak often evades detection by leveraging encryption and obfuscation techniques, making it challenging for traditional security measures to identify its presence. It primarily targets government entities, critical infrastructure, and organizations of strategic interest, with the ultimate goal of espionage, data exfiltration, and disruption of operations. Its evolving tactics highlight the growing complexity of nation-state cyber operations.
references:
- https://blog.talosintelligence.com/moonpeak-malware-infrastructure-north-korea/
tags:
category:
- Malware
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection