Jenkinson: Moonlight Maze - Cyberspace 1999 (and before)
Moonlight Maze emerged from a network of Russian servers, the operation quietly infiltrated the U.S. Department of Defense, NASA, military laboratories, universities and research institutions beginning as early as 1996.
What distinguished Moonlight Maze was not merely its reach, but its methodology: persistent access, stealthy lateral movement, encrypted data exfiltration and customised toolsets—tactics that were until then used at the time for Surveillance and became the cornerstone of modern Cyberattacks.
This campaign demonstrated that geography no longer constrained intelligence gathering.
With nothing more than computing infrastructure exploiting poorly and weakly defended networks, Russia succeeded in conducting years of reconnaissance, surveillance and intellectual-property extraction against an all too digitally trusting U.S.
Once this successful operation became visible to the global intelligence community, other states quickly grasped the strategic implications.
The barrier to entry for cyber crime and espionage had collapsed; expertise could be copied, infrastructure replicated and vulnerabilities endlessly reused.
Andy Jenkinson is on LinkedIn
at https://www.linkedin.com/in/andy-jenkinson-96210727/
The basic weaknesses exploited in the late 1990s remain present today: misconfigurations, poor authentication, inadequate monitoring and insecure DNS and PKI ecosystems.
The result is a cybersecurity landscape where nation-states and regular cyber criminals continue to exploit the same basic security failings that Moonlight Maze revealed and exploited nearly three decades ago.

