MORIYA is a Windows kernel-mode rootkit used to maintain concealed access in cyberespionage operations. It intercepts TCP traffic and identifies command-and-control packets through configurable six-byte magic sequences, allowing malicious communications and payload delivery to blend into network traffic. Observed variants inject shellcode into newly spawned Windows service-host processes. A variant used by Earth Kurma decrypts an additional payload with AES before injection and invokes thread creation through direct system calls to evade user-mode monitoring. It derives system-call numbers by enumerating native Windows API exports.
Earth Kurma deploys MORIYA on compromised systems using legitimate Windows setup components and INF-based installation. The rootkit supports stealthy persistence and payload execution; credential theft, document collection, and cloud-based exfiltration in these operations are performed by other tools rather than established capabilities of MORIYA itself.
MORIYA has been associated with Operation TunnelSnake, an espionage campaign affecting high-profile organizations in Asia and Africa, and with Earth Kurma operations targeting government and government-related telecommunications organizations in Southeast Asia, including the Philippines, Vietnam, Thailand, and Malaysia. Earth Kurma's MORIYA samples share a code base with those used in Operation TunnelSnake, but that overlap does not establish common actor attribution. A specific initial infection or distribution mechanism for MORIYA has not been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The first rootkit we observed is called MORIYA, which could hide the malicious payload in the TCP traffic.
The first rootkit we observed is called MORIYA, which could hide the malicious payload in the TCP traffic.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor component featuring updated injection and EDR evasion techniques.
TCP-intercepting rootkit that identifies command-and-control packets through configurable six-byte magic values and conceals malicious payloads in network traffic. The observed variant additionally decrypts an AES-protected payload and injects it into svchost.exe, using direct system calls for execution. It shares a code base with MORIYA used in Operation TunnelSnake, but the report does not establish common actor attribution.
Stealthy rootkit used for persistent access, network traffic interception, and malicious payload injection into system processes, with advanced evasion techniques.
Rootkit used for persistence and evasion; reported to share codebase with MORIYA used in Operation TunnelSnake and used here for stealthy data exfiltration and hiding activities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.