logo

Malicious Life Podcast: Moonlight Maze

ID: 8bd299a0-da71-553e-b65c-a35127d8c79d

STIX ID: report--8bd299a0-da71-553e-b65c-a35127d8c79d

Feed Name: Cybereason Blog

Threat Score
90/100

Date Published: 2023-12-11

Date Updated: 2026-04-27

Author: Malicious Life Podcast

...
...

This report narrates Thomas Rid’s cyber-archaeology investigation that linked the 1996–1999 Moonlight Maze espionage campaign to the Turla APT by analyzing preserved HR Test server logs and malware samples; it documents large-scale exfiltration (≈5.5GB) from ~1,600 US targets, reuse and evolution of the 1997 LOKI2 ICMP tunneling exploit into later tools (Storm Cloud, Uroburos, Agent.BTZ), and concludes Turla is a sophisticated, long-lived nation-state espionage actor active into the 21st century.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.