Wednesday, September 16, 2026
Follow on LinkedIn

Peaklight Malware Attacking Users To Exfiltrate Login Credentials, Browser History & Financial Data

A sophisticated information stealer known as Peaklight is actively targeting Windows users worldwide.

This malware, identified on March 6, 2025, is designed to harvest sensitive information from compromised endpoints, creating significant risks for both individuals and organizations.

Peaklight utilizes a flexible structure with frequent updates, making it a continuously evolving threat capable of bypassing conventional security measures.

Security experts at Wazuh have observed the malware being distributed through underground channels, with some threat actors offering it as Malware-as-a-Service (MaaS), further expanding its reach and impact across the digital landscape.

Once successfully executed on a victim’s device, Peaklight maintains persistent access while implementing multiple anti-analysis mechanisms to evade detection.

Its primary objective is to silently exfiltrate a wide range of sensitive data, including login credentials, browser history, financial information, and cryptocurrency wallet keys, all without alerting the user to its presence.

The malware’s attack sequence begins with a PowerShell script that bypasses security protocols using execution policy modifications.

Technical analysis reveals that Peaklight queries system memory using the GlobalmemoryStatusEx API call to potentially identify virtual machines or sandbox environments used for malware analysis.

The malicious code subsequently drops files with obfuscated names in user temp directories and allocates multiple 4-8 KB blocks of read-write-execute memory to enable code execution.

Detection and Protection Strategies

Security researchers have identified Peaklight through its distinctive behaviors, including suspicious registry modifications and DLL injections.

The malware can be identified by its hash signatures: MD5 (95361f5f264e58d6ca4538e7b436ab67) and SHA256 (07061f3fd8c15bdd484b55baa44191aa9d045c9889234550939f46c063e6211c).

Organizations can implement detection capabilities using monitoring tools like Sysmon with custom configuration.

For example, the following PowerShell command can be used to install Sysmon with appropriate monitoring rules:-

.\Sysmon64.exe -accepteula -i sysmonconfig.xml

Security platforms like Wazuh have developed custom YARA rules to detect Peaklight’s presence through signature-based scanning.

Security dashboards (Source – Wazuh)

These rules identify suspicious patterns such as AES encryption functions and obfuscated PowerShell commands often used by the malware. When properly configured, security dashboards can provide real-time alerts when Peaklight-related activities are detected on monitored endpoints.

To mitigate risk, security experts recommend implementing comprehensive endpoint monitoring, keeping systems updated, and utilizing threat detection tools capable of identifying the specific behavioral patterns associated with this evolving threat.

Are you from SOC/DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.

Tushar Subhra Dutta
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Cyber Security Guide

Latest Cyber News

Expert Talks