MoriAgent

First seen
2019-06-01 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 13:22:49

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:jp country_code:us

Context

MoriAgent is a sophisticated remote access trojan used primarily in cyber-espionage campaigns. It targets government and defense sectors, with notable activity in Japan and the United States.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Apt_Muddywater_Moriagent (yara-rule)
  • MALPEDIA_Win_Moriagent_Auto (yara-rule)

Reports & references

  • CISA — Aa22 055A (report)
  • cybercom.mil — Iranian Intel Cyber Suite Of Malware Uses Open Source Tools (report)
  • Kaspersky — 99204 (report)
  • CISA — Aa22 055A Iranian Government Sponsored Actors Conduct Cyber Operations (report)
  • inforisktoday.com — Muddywater Targets Critical Infrastructure In Asia Europe A 18611 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Moriagent (report)
  • live.paloaltonetworks.com — 326590 (report)
  • twitter.com — 1272776776335233024 (report)

External references