Uptime Hamster: 10d 9h 53mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza UAT-5394

UAT-5394

0 incidentes 0 paises 0 sectores apt KP Ultimo: -
Aliases: APT-C-55, Black Banshee, HancomAgent, HttpTroy, Larva-25004, RftRAT, Velvet Chollima, archipelago, blindingcan, comebacker, emerald sleet
Ver en IntelTracker → APTTrail →
UAT-5394 is a state-sponsored North Korean threat actor known for the continuous development and deployment of MoonPeak, a custom Remote Access Trojan (RAT) derived from the open-source XenoRAT. This group emerged with observed MoonPeak testing activities in January 2024 and subsequently established its infrastructure, initially using QuasarRAT before transitioning to MoonPeak. UAT-5394's primary motivation is assessed to be espionage, data exfiltration, and disruption of operations. What distinguishes UAT-5394 is its rapid and sustained evolution of the MoonPeak RAT, incorporating frequent obfuscation, communication tweaks, and the implementation of State Machines to complicate analysis. The group also demonstrates adaptability by shifting its infrastructure from legitimate cloud services to attacker-owned systems following public disclosures to maintain operational secrecy. While UAT-5394 exhibits significant overlaps in tactics, techniques, and procedures (TTPs) and infrastructure p

Aliases del actor

APT-C-55Black BansheeHancomAgentHttpTroyLarva-25004RftRATVelvet Chollimaarchipelagoblindingcancomebackeremerald sleet

Actores similares

apt-blackgearactor · 1apt-blacktechactor · 1apt-equationgroupactor · 1apt-onyxsleetactor · 1apt-45actor · 2apt-c-27actor · 2apt-c-01actor · 2apt-c-12actor · 1apt-18actor · 1apt-1877teamactor · 1
Tipo
apt
Pais origen
KP
Motivacion
-
Impacto
-
Actualizado
Thu, 09 Ap

Sectores objetivo (SOCRadar)

Employment Placement Agencies and Executive Search Services