PEAKLIGHT Downloader
Summary
Cybersecurity researchers have discovered a novel dropper designed to deploy subsequent malware stages, ultimately targeting Windows systems with information stealers and loaders. Once downloaded, the LNK file connects to a Content Delivery Network (CDN) that hosts an obfuscated, memory-only JavaScript dropper. This dropper then executes the PEAKLIGHT PowerShell downloader script on the victims machine, which, in turn, contacts a Command-and-Control (C2) server to retrieve further payloads. Researchers have observed various LNK file variations, with some using asterisks (*) as wildcards to invoke the legitimate mshta.exe binary, allowing the malicious code (i.e., the dropper) to be discreetly executed from a remote server. These payloads are unpacked to run PEAKLIGHT, a tool designed to deploy subsequent malware on an infected system while also downloading a legitimate movie trailer, likely as a decoy.