UAT-5394 is a state-sponsored North Korean threat actor known for the continuous development and deployment of MoonPeak, a custom Remote Access Trojan (RAT) derived from the open-source XenoRAT. This group emerged with observed MoonPeak testing activities in January 2024 and subsequently established its infrastructure, initially using QuasarRAT before transitioning to MoonPeak. UAT-5394's primary motivation is assessed to be espionage, data exfiltration, and disruption of operations. What distinguishes UAT-5394 is its rapid and sustained evolution of the MoonPeak RAT, incorporating frequent obfuscation, communication tweaks, and the implementation of State Machines to complicate analysis. The group also demonstrates adaptability by shifting its infrastructure from legitimate cloud services to attacker-owned systems following public disclosures to maintain operational secrecy. While UAT-5394 exhibits significant overlaps in tactics, techniques, and procedures (TTPs) and infrastructure p