UAT-5394

Origin
KP
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:17:31

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services energy-and-utilities defense-and-aerospace

Targeted regions: country_code:us country_code:kr country_code:jp

Context

UAT-5394 is a state-sponsored North Korean threat actor known for developing the MoonPeak RAT, which is based on XenoRAT. They have transitioned from using QuasarRAT to MoonPeak and have established command and control infrastructure. UAT-5394 employs tactics such as using RDP for remote access and has implemented State Machines in their malware to complicate analysis. Their activity indicates a focus on rapidly evolving their malware and infrastructure to enhance operational capabilities.

Reports & references

  • Cisco Talos — Moonpeak Malware Infrastructure North Korea (report)

External references