{"id":2662,"date":"2021-05-11T21:38:21","date_gmt":"2021-05-12T02:38:21","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2662"},"modified":"2021-05-11T21:38:22","modified_gmt":"2021-05-12T02:38:22","slug":"moriya-is-a-new-rootkit-that-uses-back-doors","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/","title":{"rendered":"Moriya is a new rootkit that uses back doors"},"content":{"rendered":"\n<p>Rootkits are malicious tools designed to evade detection by burying deep into the operating system and used by attackers to take full control of infected systems avoiding detection and it is there that a new unknown threat actor used a new stealthy rootkit known now. like Moriya, to backdoor Windows systems targeting what appears to be an ongoing spy campaign.<\/p>\n\n\n\n<p>In a campaign dubbed Operation TunnelSnake by Kaspersky researchers, the team said Thursday that a group of advanced persistent threats, of unknown origin but suspected of being Chinese-speaking, have used the rootkit to silently take control of the networks they belong to.<\/p>\n\n\n\n<p>According to Kaspersky, the newly discovered rootkit, called Moriya, is used to implement passive back doors on public servers. The back doors are then used to silently establish a connection to a command and control (C2) server controlled by malicious threat actors. The backdoor allows attackers to monitor all inbound and outbound traffic passing through an infected machine and filter packets sent by malware.<\/p>\n\n\n\n<p>Moriya allowed TunnelSnake operators to capture and analyze incoming network traffic &#8220;from the Windows kernel address space, a region of memory where the operating system kernel resides and where only privileged and trusted code runs normally.&#8221; .   The way the backdoor received commands in the form of custom packets hidden in the victims&#8217; network traffic, without the need to contact a command-and-control server, added to the stealth of the operation shown by the victim care.<\/p>\n\n\n\n<p>The threat actor used backdoor systems belonging to Asian and African diplomatic entities and other high-profile organizations to gain control of their networks and maintain persistence for months without being detected.   Additionally, the attackers deployed additional tools (including China Chopper, BOUNCER, Termite, and Earthworm) during the post-exploit phase on the compromised systems. This allowed them to move laterally on the network after scanning and finding new vulnerable hosts on the victims&#8217; networks.<\/p>\n\n\n\n<p>See also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/rootkit-what-you-should-know-about-it\/\">Rootkit \u2013 What you should know about it?<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/cold-boot-attack-a-risk-to-our-information\/\">Cold Boot Attack \u2013 A risk to our information<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Rootkits are malicious tools designed to evade detection by burying deep into the operating system and used by attackers to take full control of infected systems avoiding detection and it is there that a new unknown threat actor used a new stealthy rootkit known now. like Moriya, to backdoor Windows systems targeting what appears to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2663,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2662","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Moriya is a new rootkit that uses back doors - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"A new rootkit that arises which is known as Moriya also, it is thought that it has been present since 2018 although it is not known 100%.....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Moriya is a new rootkit that uses back doors - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"A new rootkit that arises which is known as Moriya also, it is thought that it has been present since 2018 although it is not known 100%.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-12T02:38:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-05-12T02:38:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/rootkitt.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/moriya-is-a-new-rootkit-that-uses-back-doors\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/moriya-is-a-new-rootkit-that-uses-back-doors\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Moriya is a new rootkit that uses back doors\",\"datePublished\":\"2021-05-12T02:38:21+00:00\",\"dateModified\":\"2021-05-12T02:38:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/moriya-is-a-new-rootkit-that-uses-back-doors\\\/\"},\"wordCount\":338,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/moriya-is-a-new-rootkit-that-uses-back-doors\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/rootkitt.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/moriya-is-a-new-rootkit-that-uses-back-doors\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/moriya-is-a-new-rootkit-that-uses-back-doors\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/moriya-is-a-new-rootkit-that-uses-back-doors\\\/\",\"name\":\"Moriya is a new rootkit that uses back doors - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/moriya-is-a-new-rootkit-that-uses-back-doors\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/moriya-is-a-new-rootkit-that-uses-back-doors\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/rootkitt.jpg\",\"datePublished\":\"2021-05-12T02:38:21+00:00\",\"dateModified\":\"2021-05-12T02:38:22+00:00\",\"description\":\"A new rootkit that arises which is known as Moriya also, it is thought that it has been present since 2018 although it is not known 100%.....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/moriya-is-a-new-rootkit-that-uses-back-doors\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/moriya-is-a-new-rootkit-that-uses-back-doors\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/moriya-is-a-new-rootkit-that-uses-back-doors\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/rootkitt.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/rootkitt.jpg\",\"width\":800,\"height\":400},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/moriya-is-a-new-rootkit-that-uses-back-doors\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Moriya is a new rootkit that uses back doors\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Moriya is a new rootkit that uses back doors - Truxgo Server Blog","description":"A new rootkit that arises which is known as Moriya also, it is thought that it has been present since 2018 although it is not known 100%.....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/","og_locale":"es_MX","og_type":"article","og_title":"Moriya is a new rootkit that uses back doors - Truxgo Server Blog","og_description":"A new rootkit that arises which is known as Moriya also, it is thought that it has been present since 2018 although it is not known 100%.....","og_url":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-05-12T02:38:21+00:00","article_modified_time":"2021-05-12T02:38:22+00:00","og_image":[{"width":800,"height":400,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/rootkitt.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Moriya is a new rootkit that uses back doors","datePublished":"2021-05-12T02:38:21+00:00","dateModified":"2021-05-12T02:38:22+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/"},"wordCount":338,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/rootkitt.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/","url":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/","name":"Moriya is a new rootkit that uses back doors - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/rootkitt.jpg","datePublished":"2021-05-12T02:38:21+00:00","dateModified":"2021-05-12T02:38:22+00:00","description":"A new rootkit that arises which is known as Moriya also, it is thought that it has been present since 2018 although it is not known 100%.....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/rootkitt.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/rootkitt.jpg","width":800,"height":400},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/moriya-is-a-new-rootkit-that-uses-back-doors\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Moriya is a new rootkit that uses back doors"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2662","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2662"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2662\/revisions"}],"predecessor-version":[{"id":2671,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2662\/revisions\/2671"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2663"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2662"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2662"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2662"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}