Moonlight Maze
loresecurityhacking
The intrusion campaign discovered in 1998 that had been quietly reading US military, NASA, Department of Energy and university systems since at least 1996 - the first sustained state-scale espionage operation ever detected on the internet, and the effective birth of the category later called the advanced persistent threat.
Investigators traced connections toward Moscow; attribution was never made public with proof, and Russia denied involvement. What makes it foundational is the shape rather than the source: patient, low-noise, years-long access focused on collection rather than damage, using ordinary Unix vulnerabilities and stolen credentials. Researchers in 2016 linked surviving Moonlight Maze code to the Turla toolkit still in use two decades later, which is the clearest evidence anyone has that state operations have continuity measured in generations.
Also known as: 1996 intrusions, first apt, storm cloud