A sophisticated information stealer known as Peaklight is actively targeting Windows users worldwide.
This malware, identified on March 6, 2025, is designed to harvest sensitive information from compromised endpoints, creating significant risks for both individuals and organizations.
Peaklight utilizes a flexible structure with frequent updates, making it a continuously evolving threat capable of bypassing conventional security measures.
Security experts at Wazuh have observed the malware being distributed through underground channels, with some threat actors offering it as Malware-as-a-Service (MaaS), further expanding its reach and impact across the digital landscape.
Once successfully executed on a victim’s device, Peaklight maintains persistent access while implementing multiple anti-analysis mechanisms to evade detection.
Its primary objective is to silently exfiltrate a wide range of sensitive data, including login credentials, browser history, financial information, and cryptocurrency wallet keys, all without alerting the user to its presence.
The malware’s attack sequence begins with a PowerShell script that bypasses security protocols using execution policy modifications.
Technical analysis reveals that Peaklight queries system memory using the GlobalmemoryStatusEx API call to potentially identify virtual machines or sandbox environments used for malware analysis.
The malicious code subsequently drops files with obfuscated names in user temp directories and allocates multiple 4-8 KB blocks of read-write-execute memory to enable code execution.
Security researchers have identified Peaklight through its distinctive behaviors, including suspicious registry modifications and DLL injections.
The malware can be identified by its hash signatures: MD5 (95361f5f264e58d6ca4538e7b436ab67) and SHA256 (07061f3fd8c15bdd484b55baa44191aa9d045c9889234550939f46c063e6211c).
Organizations can implement detection capabilities using monitoring tools like Sysmon with custom configuration.
For example, the following PowerShell command can be used to install Sysmon with appropriate monitoring rules:-
.\Sysmon64.exe -accepteula -i sysmonconfig.xml Security platforms like Wazuh have developed custom YARA rules to detect Peaklight’s presence through signature-based scanning.
These rules identify suspicious patterns such as AES encryption functions and obfuscated PowerShell commands often used by the malware. When properly configured, security dashboards can provide real-time alerts when Peaklight-related activities are detected on monitored endpoints.
To mitigate risk, security experts recommend implementing comprehensive endpoint monitoring, keeping systems updated, and utilizing threat detection tools capable of identifying the specific behavioral patterns associated with this evolving threat.
Are you from SOC/DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…