Malicious Life Podcast: Moonlight Maze
ID: 8bd299a0-da71-553e-b65c-a35127d8c79d
STIX ID: report--8bd299a0-da71-553e-b65c-a35127d8c79d
Feed Name: Cybereason Blog
This report narrates Thomas Rid’s cyber-archaeology investigation that linked the 1996–1999 Moonlight Maze espionage campaign to the Turla APT by analyzing preserved HR Test server logs and malware samples; it documents large-scale exfiltration (≈5.5GB) from ~1,600 US targets, reuse and evolution of the 1997 LOKI2 ICMP tunneling exploit into later tools (Storm Cloud, Uroburos, Agent.BTZ), and concludes Turla is a sophisticated, long-lived nation-state espionage actor active into the 21st century.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
