Moriya
- First seen
- 2018-11-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 13:10:29
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
This tool is a passive backdoor which allows attackers to inspect all incoming traffic to the infected machine, filter out packets that are marked as designated for the malware and respond to them. This forms a covert channel over which attackers are able to issue shell commands and receive back their outputs.
Detection coverage
- 3 YARA rules
Detection rules
- ARKBIRD_SOLG_MAL_Moriya_May_2021_1 (yara-rule)
- ARKBIRD_SOLG_MAL_Moriya_May_2021_2 (yara-rule)
- MALPEDIA_Win_Moriya_Auto (yara-rule)
Reports & references
- Kaspersky — 101831 (report)
- Trend Micro — Earth Kurma Apt Campaign (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Moriya (report)