← All Threat Actors
Threat Actor Profile

MuddyWater

ATK51 Boggy Serpens COBALT ULSTER Earth Vetala G0069 Mango Sandstorm MERCURY MuddyKrill Seedworm Static Kitten TA450 TEMP.Zagros
▲ High Threat
The MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including targets in India and the USA. MuddyWater attacks are characterized by the use of a slowly evolving PowerShell-based first stage backdoor we call “POWERSTATS”. Despite broad scrutiny and reports on MuddyWater attacks, the activity continues with only incremental changes to the tools and techniques.
Origin Iran
Sponsor Iran (Islamic Republic of)
Motivation Espionage

Target Sectors

Government

Known TTPs

Spearphishing Link
Office Template Macros
DLL
Tool
Mshta
Malicious Copy and Paste
Windows Management Instrumentation
Internal Spearphishing
LSA Secrets
Spearphishing Attachment
Domains
Network Topology
Component Object Model
Non-Standard Port
Windows Command Shell
Malware
CMSTP
Match Legitimate Resource Name or Location
Domain Account
JavaScript
Web Services
Visual Basic
System Network Configuration Discovery
Registry Run Keys / Startup Folder
Deobfuscate/Decode Files or Information
Dynamic Data Exchange
Command Obfuscation
Compile After Delivery
Security Software Discovery
Local Data Staging
Screen Capture
Web Protocols
Disable or Modify Tools
Software Discovery
File and Directory Discovery
Bypass User Account Control
Ingress Tool Transfer
Symmetric Cryptography
Exfiltration to Cloud Storage
Credentials from Web Browsers
Phishing
Archive via Utility
Impersonation
Python
System Network Connections Discovery
System Information Discovery
Credentials from Password Stores
Process Discovery
Standard Encoding
Multi-Stage Channels
Proxy
Malicious Link
Steganography
LSASS Memory
Scheduled Task
External Proxy
Malicious File
System Owner/User Discovery
Remote Desktop Software
Exfiltration Over C2 Channel
PowerShell
Bidirectional Communication
Rundll32
Credentials In Files
Exploit Public-Facing Application
Exploitation of Remote Services
Exploitation for Client Execution
Cached Domain Credentials

Related Intelligence

Hacking the mainframe…

LINK COPIED TO CLIPBOARD