<\/gwmw><\/figcaption><\/figure>\n\n\n\nSince June 11, 2024, UAT-5394 shifted their tactics by moving from using legitimate cloud storage to their own controlled infrastructure to avoid shutdowns by service providers. They set up one of their earliest servers, 95.164.86.148, on June 12, 2024, to host malicious artifacts and operate as a MoonPeak C2 server. This server was accessed via RDP by another server, 27.255.81.118, which was linked to multiple malicious domains. On July 5, 2024, they used 95.164.86.148 to RDP into another server, 167.88.173.173, deploying MoonPeak C2 on additional ports.<\/p>\n\n\n\n
“An analysis of MoonPeak samples reveals an evolution in the malware and its corresponding C2 components that warranted the threat actors deploy their implant variants several times on their test machines. The constant evolution of MoonPeak runs hand-in-hand with new infrastructure set up by the threat actors.” states the report published by Talos. “Each new increment of MoonPeak differs from the previous one in two aspects:\u00a0<\/p>\n\n\n\n