Researchers from Kaspersky Lab and King 's College London, looking into how a modern threat actor is connected to the Moonlight Maze attacks that targeted the Pentagon, NASA , and other organizations in the late 1990s, have uncovered samples, logs, and artifacts belonging to the "ancient" APT attack .
The findings show that a backdoor used in 1998 by Moonlight Maze to funnel information outside the victims' network is linked to a backdoor used by Turla in 2011 and, possibly, as far back as 2017.
If the connection between Turla and Moonlight Maze is proven, it would place the advanced threat actor alongside the Equation Group in terms of its longevity, as some of Equation date back to 1996.
Contemporary reports on the Moonlight Maze indicate that, starting in 1996, U.S. military and government networks, as well as universities, research institutions, and even the Department of Energy, began to detect breaches in their systems. In 1998, the FBI and the Department of Defense launched a massive investigation. The story was made public in 1999, but much of the evidence remained classified, maintaining top-secret secrecy and leaving the details of the Moonlight Maze a myth.
Over the years, original researchers in three different countries have stated that Moonlight Maze evolved into Turla, a Russian-speaking threat actor also known as Snake, Uroburos, Venomous Bear, and Krypton. Turla is conventionally considered to have been active since 2007.
Moonlight Maze: The "forgotten" specimens
In 2016, Thomas Rid of King’s College London, while researching his book “Rise of the Machines,” tracked down a former system administrator whose work server had been hijacked as a proxy by the Moonlight Maze attackers. This server, named “HRTest,” had been used to launch attacks in the United States. The now-retired IT professional had kept the original server and copies of everything related to the attacks, which he gave to King’s College and Kaspersky Lab for further analysis.
Kaspersky Lab researchers Juan Andres Guerrero-Saade and Costin Raiu, along with Thomas Rid and Danny Moore from King's College, spent nine months conducting a detailed technical analysis of these samples. They reconstructed the attackers' operations, tools, and techniques, and conducted a parallel investigation to see if they could prove the alleged connection toTurla .
Moonlight Maze was an open - source, Unix - based attack targeting Solaris systems , with findings indicating that it likely exploited a vulnerability in LOKI 2 (a program released in 1996 that allowed users to extract data from covert channels). This led researchers to take a second look at some rare Linux samples used by Turla , which Kaspersky Lab had discovered in 2014. Dubbed Penquin Turla , the samples are also based on LOKI2. The re-examination also showed that they all used code created between 1999 and 2004.
It is noteworthy that this code is still used in attacks today. It was found free on the Internet in 2011, where it was carrying out an attack on the Swiss defense company Ruag, an attack attributed to Turla. Then, in March 2017, Kaspersky Lab researchers discovered a new sample of the backdoor on a system in Germany. It is possible that Turla is using the old code to attack high-security organizations, as it may be harder to hack using more typical Windows tools.
“In the late 1990s, no one predicted the scope and persistence of a coordinated digital espionage campaign. We must ask ourselves why attackers are still able to successfully exploit ‘ancient’ code for modern attacks. The analysis of the Moonlight Maze is not just a fascinating archaeological study. It is also a reminder that well-sourced adversaries are not going anywhere. It is up to us to defend systems by developing the right skills,” said Juan Andres Guerrero–Saade, Security Researcher in the Global Research and Analysis Team at Kaspersky Lab.
The recently released Moonlight Maze files revealed many fascinating details about how the attacks were carried out using a complex network of proxies, and the high level of skills and tools used by the attackers
More information about the Moonlight Maze attack sequence and its typology can be seen below:
For more information Securelist.com,website you can read the blogpost on the dedicated .
