MORIYA is a Windows kernel-mode rootkit used for stealthy persistence and payload execution in cyberespionage intrusions. It intercepts TCP traffic and identifies specially formatted trigger data, allowing operators to conceal malicious payload delivery within network communications. MORIYA decrypts embedded payloads and injects shellcode into a Windows service-host process; reported variants use direct system calls and updated injection methods intended to evade endpoint detection and response products. MORIYA has been deployed by the Earth Kurma threat actor against government and telecommunications organizations in Southeast Asia. Its code base overlaps with MORIYA rootkits used in Operation TunnelSnake, although this overlap alone does not establish common attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The kernel-level MORIYA rootkit inspects TCP packets for ‘magic bytes’ then injects shellcode into svchost.exe.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor component featuring updated injection and EDR evasion techniques.
Stealthy rootkit used for persistent access, network traffic interception, and malicious payload injection into system processes, with advanced evasion techniques.
Rootkit used for persistence and evasion; reported to share codebase with MORIYA used in Operation TunnelSnake and used here for stealthy data exfiltration and hiding activities.
Kernel-level rootkit that inspects inbound TCP traffic for a malicious payload and injects shellcode into a newly spawned svchost.exe process; used to maintain stealthy persistence and enable follow-on activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.