Moonlight Maze was a long-running cyberespionage campaign first identified in the late 1990s and widely regarded as one of the earliest publicly known state-sponsored intrusions. Activity began as early as 1996 and primarily targeted U.S. military, government, research, and university networks, including defense and civilian agencies. The operation has long been associated with Russian or Russian state-sponsored actors, although some later lineage claims connecting it to Turla remain suggestive rather than definitive. The campaign relied heavily on Unix and Solaris/IRIX tradecraft rather than Windows malware. Operators used compromised third-party systems as relay and staging infrastructure to obscure origin, manually logged into victim environments, and deployed tool archives containing public exploits, open-source utilities, custom binaries, and scripts. Initial access and privilege escalation frequently depended on opportunistic exploitation of exposed services and repeated trial-and-error execution of local privilege-escalation exploits after foothold establishment. Moonlight Maze operators demonstrated mature post-compromise capability for the period. Their tooling included packet sniffers for harvesting credentials from insecure protocols, X11 keylogging, covert-channel backdoors derived from LOKI2, tunnel and redirector components, log cleaners, and scripts for host survey, tasking, collection, and exfiltration support. A recurring operational pattern was pseudo-automation through task files stored in temporary directories, allowing malware and scripts to read commands and configuration locally. The group also used utilities to remove traces from authentication and accounting logs and reviewed forensic artifacts to assess operational exposure. The intrusion set evolved over time, with multiple related Solaris and IRIX toolkits showing iterative development, porting, and refinement of stealth and functionality. Researchers have highlighted a technical lineage between Moonlight Maze LOKI2-derived tooling and Penquin Turla, a Linux backdoor associated with the Russian-speaking Turla espionage actor, and have suggested Storm Cloud as a possible bridging phase. That continuity hypothesis is technically plausible and supported by shared Unix-focused tradecraft, but it is not conclusively proven. Moonlight Maze remains best characterized as an early Russian-linked cyberespionage operation focused on large-scale theft of sensitive government and research information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
49 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historic cyberespionage campaign targeting U.S. military, research, and university networks. Operators used hacked relay servers, Unix tooling, tasking files, sniffers, manual operator-at-keyboard activity, and open-source backdoors/exploits. The content explores whether this activity evolved into Turla.
State-sponsored cyber espionage campaign that hijacked a London HR company web server as a proxy to attack more than a thousand US government and military systems and steal sensitive data, including weapons-guidance and naval intelligence information.
Conducted intrusions in 1998-1999 using tool archives containing backdoors, sniffers, keyloggers, tunnel redirectors, log cleaners, reconnaissance scripts, and privilege-escalation exploits across SunOS/Solaris and IRIX systems, with an emphasis on covert communications, credential capture, persistence, log tampering, and data exfiltration.
Historic cyberespionage campaign active from at least 1996 targeting U.S. military, government, and academic networks. Operators used relay servers, public exploits, Solaris/*nix tooling, sniffers, LOKI2-derived covert channels, credential theft, lateral movement, log cleaning, and manual/operator-intensive tradecraft to exfiltrate sensitive data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.