A technical appendix on the Moonlight Maze intrusions details how operators used a broad toolkit during attacks routed through the HRTest relay, combining custom malware with modified public exploit code across SunOS SPARC and IRIX MIPS systems. The material catalogs 45 binaries and 9 scripts used for reconnaissance, privilege escalation, covert communications, credential theft, and exfiltration support, showing a mature and adaptable intrusion capability rather than isolated use of single-purpose tools.
The toolkit included LOKI2-derived ICMP backdoors, tcpdump/libpcap-based sniffers, X11 keylogging, and utilities designed to erase evidence by cleaning utmp, wtmp, and lastlog records. Repeated operational patterns included use of /var/tmp task files for command-and-control, while multiple variants—such as ETAR1, SPTAR, LUTAR, IMI, IMTAR, ITDN, STDN, and STR—showed iterative development and porting between Solaris and IRIX environments; the appendix also notes Russian-derived naming and broken-English strings that point to ongoing operator customization of the toolchain.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
The report analyzes artifacts from Moonlight Maze intrusions conducted through the “HRTest” relay during 1998–1999. It documents the operators’ use of custom malware, modified public exploit code, and scripts across compromised systems.
The report states that Moonlight Maze intrusions began as early as 1996 and targeted U.S. military and government organizations. Named victims included Wright Patterson Air Force Base, Kelly Air Force Base, the Army Research Lab, Naval Sea Systems Command in Indian Head, NASA, and Department of Energy laboratories.
A forensic analysis of archived Moonlight Maze artifacts concluded that the campaign likely evolved into the modern Turla threat actor through a shared LOKI2-derived Unix/Linux malware lineage, with Storm Cloud as a probable bridge. The report also revised earlier understanding of Penquin Turla, assessing it as derived from LOKI2 rather than cd00r.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.