MoriAgent
- First seen
- 2019-06-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 13:22:49
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:jp country_code:us
Context
MoriAgent is a sophisticated remote access trojan used primarily in cyber-espionage campaigns. It targets government and defense sectors, with notable activity in Japan and the United States.
Detection coverage
- 2 YARA rules
Detection rules
- SEKOIA_Apt_Muddywater_Moriagent (yara-rule)
- MALPEDIA_Win_Moriagent_Auto (yara-rule)
Reports & references
- CISA — Aa22 055A (report)
- cybercom.mil — Iranian Intel Cyber Suite Of Malware Uses Open Source Tools (report)
- Kaspersky — 99204 (report)
- CISA — Aa22 055A Iranian Government Sponsored Actors Conduct Cyber Operations (report)
- inforisktoday.com — Muddywater Targets Critical Infrastructure In Asia Europe A 18611 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Moriagent (report)
- live.paloaltonetworks.com — 326590 (report)
- twitter.com — 1272776776335233024 (report)