Moriya

First seen
2018-11-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 13:10:29

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

This tool is a passive backdoor which allows attackers to inspect all incoming traffic to the infected machine, filter out packets that are marked as designated for the malware and respond to them. This forms a covert channel over which attackers are able to issue shell commands and receive back their outputs.

Detection coverage

  • 3 YARA rules

Detection rules

  • ARKBIRD_SOLG_MAL_Moriya_May_2021_1 (yara-rule)
  • ARKBIRD_SOLG_MAL_Moriya_May_2021_2 (yara-rule)
  • MALPEDIA_Win_Moriya_Auto (yara-rule)

Reports & references

  • Kaspersky — 101831 (report)
  • Trend Micro — Earth Kurma Apt Campaign (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Moriya (report)

External references