Cyber Security News

Peaklight Malware Attacking Users To Exfiltrate Login Credentials, Browser History & Financial Data

A sophisticated information stealer known as Peaklight is actively targeting Windows users worldwide.

This malware, identified on March 6, 2025, is designed to harvest sensitive information from compromised endpoints, creating significant risks for both individuals and organizations.

Peaklight utilizes a flexible structure with frequent updates, making it a continuously evolving threat capable of bypassing conventional security measures.

Security experts at Wazuh have observed the malware being distributed through underground channels, with some threat actors offering it as Malware-as-a-Service (MaaS), further expanding its reach and impact across the digital landscape.

Once successfully executed on a victim’s device, Peaklight maintains persistent access while implementing multiple anti-analysis mechanisms to evade detection.

Its primary objective is to silently exfiltrate a wide range of sensitive data, including login credentials, browser history, financial information, and cryptocurrency wallet keys, all without alerting the user to its presence.

The malware’s attack sequence begins with a PowerShell script that bypasses security protocols using execution policy modifications.

Technical analysis reveals that Peaklight queries system memory using the GlobalmemoryStatusEx API call to potentially identify virtual machines or sandbox environments used for malware analysis.

The malicious code subsequently drops files with obfuscated names in user temp directories and allocates multiple 4-8 KB blocks of read-write-execute memory to enable code execution.

Detection and Protection Strategies

Security researchers have identified Peaklight through its distinctive behaviors, including suspicious registry modifications and DLL injections.

The malware can be identified by its hash signatures: MD5 (95361f5f264e58d6ca4538e7b436ab67) and SHA256 (07061f3fd8c15bdd484b55baa44191aa9d045c9889234550939f46c063e6211c).

Organizations can implement detection capabilities using monitoring tools like Sysmon with custom configuration.

For example, the following PowerShell command can be used to install Sysmon with appropriate monitoring rules:-

.\Sysmon64.exe -accepteula -i sysmonconfig.xml

Security platforms like Wazuh have developed custom YARA rules to detect Peaklight’s presence through signature-based scanning.

Security dashboards (Source – Wazuh)

These rules identify suspicious patterns such as AES encryption functions and obfuscated PowerShell commands often used by the malware. When properly configured, security dashboards can provide real-time alerts when Peaklight-related activities are detected on monitored endpoints.

To mitigate risk, security experts recommend implementing comprehensive endpoint monitoring, keeping systems updated, and utilizing threat detection tools capable of identifying the specific behavioral patterns associated with this evolving threat.

Are you from SOC/DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

58 minutes ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

11 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

12 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

12 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago