MORIYA is a rootkit/backdoor component used in cyberespionage operations, notably by the Earth Kurma APT targeting government and telecommunications organizations in Southeast Asia, including the Philippines, Vietnam, Thailand, and Malaysia. Trend Micro reported Earth Kurma activity from at least June 2024, with indications the group may have operated since 2020. MORIYA has also been linked by code-base overlap to the MORIYA rootkit used in Operation TunnelSnake, and reporting notes it was previously observed in attacks against high-profile organizations in Asia and Africa.
Its core capability is stealthy network interception: MORIYA inspects incoming TCP packets for a malicious payload and can hide payloads within TCP traffic. It injects shellcode or AES-encrypted payloads into newly spawned svchost.exe processes, functioning as a TCP traffic interceptor that can inject malicious payloads into network responses while remaining difficult to detect. Reported tradecraft includes new injection methods, EDR evasion techniques, and the use of direct system calls to bypass detection. In the Earth Kurma intrusion chain, MORIYA was deployed after initial compromise as part of a broader toolset that included loaders such as DUNLOADER, TESDAT, and DMLOADER, Cobalt Strike Beacons, the KRNRAT rootkit, reconnaissance and lateral movement tools, and cloud-based exfiltration malware.
Within Earth Kurma operations, MORIYA supported stealthy persistence and concealment of malicious activity. The campaign used living-off-the-land techniques, including syssetup.dll, to install rootkits, and focused on espionage, credential theft, and data exfiltration via services such as Dropbox and OneDrive. High-confidence behavioral details directly stated in the source are that MORIYA is a rootkit sharing the same code base as the TunnelSnake variant, acts as a TCP traffic interceptor, hides malicious payloads in TCP traffic, and injects shellcode or AES-encrypted payloads into svchost.exe while employing injection and EDR-evasion techniques.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...rootkits such as KRNRAT and Moriya... While Moriya is engineered to inspect incoming TCP packets for a malicious payload and inject shellcode into a newly spawned "svchost.exe" process...
3 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor component featuring updated injection and EDR evasion techniques.
Stealthy rootkit used for persistent access, network traffic interception, and malicious payload injection into system processes, with advanced evasion techniques.
Rootkit used for persistence and evasion; reported to share codebase with MORIYA used in Operation TunnelSnake and used here for stealthy data exfiltration and hiding activities.
Kernel-level rootkit that inspects inbound TCP traffic for a malicious payload and injects shellcode into a newly spawned svchost.exe process; used to maintain stealthy persistence and enable follow-on activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.