Real-world descriptions of how a group, tool or campaign used a technique.
68 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupMuddyWater | MuddyWater has performed credential dumping with Mimikatz and procdump64.exe. |
| T1003.004 LSA Secrets |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne. |
| T1003.005 Cached Domain Credentials |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne. |
| T1016 System Network Configuration Discovery |
GroupMuddyWater | MuddyWater has used malware to collect the victim’s IP address and domain name. |
| T1027.003 Steganography |
GroupMuddyWater | MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg. |
| T1027.004 Compile After Delivery |
GroupMuddyWater | MuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code. |
| T1027.010 Command Obfuscation |
GroupMuddyWater | MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands. |
| T1033 System Owner/User Discovery |
GroupMuddyWater | MuddyWater has used malware that can collect the victim’s username. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMuddyWater | MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender. |
| T1041 Exfiltration Over C2 Channel |
GroupMuddyWater | MuddyWater has used C2 infrastructure to receive exfiltrated data. |
| T1047 Windows Management Instrumentation |
GroupMuddyWater | MuddyWater has used malware that leveraged WMI for execution and querying host information. |
| T1049 System Network Connections Discovery |
GroupMuddyWater | MuddyWater has used a PowerShell backdoor to check for Skype connections on the target machine. |
| T1053.005 Scheduled Task |
GroupMuddyWater | MuddyWater has used scheduled tasks to establish persistence. |
| T1057 Process Discovery |
GroupMuddyWater | MuddyWater has used malware to obtain a list of running processes on the system. |
| T1059.001 PowerShell |
GroupMuddyWater | MuddyWater has used PowerShell for execution. ClearSky MuddyWater Nov 2018DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018MuddyWater TrendMicro June 2018NaumaanProofpoint_GlobalClickFix_April2025Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Symantec MuddyWater Dec 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021 |
| T1059.003 Windows Command Shell |
GroupMuddyWater | MuddyWater has used a custom tool for creating reverse shells. |
| T1059.005 Visual Basic |
GroupMuddyWater | MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros. |
| T1059.006 Python |
GroupMuddyWater | MuddyWater has developed tools in Python including Out1. |
| T1059.007 JavaScript |
GroupMuddyWater | MuddyWater has used JavaScript files to execute its POWERSTATS payload. |
| T1071.001 Web Protocols |
GroupMuddyWater | MuddyWater has used HTTP for C2 communications. |
| T1074.001 Local Data Staging |
GroupMuddyWater | MuddyWater has stored a decoy PDF file within a victim's `%temp%` folder. |
| T1082 System Information Discovery |
GroupMuddyWater | MuddyWater has used malware that can collect the victim’s OS version and machine name. |
| T1083 File and Directory Discovery |
GroupMuddyWater | MuddyWater has used malware that checked if the ProgramData folder had folders or files with the keywords "Kasper," "Panda," or "ESET." |
| T1087.002 Domain Account |
GroupMuddyWater | MuddyWater has used |
| T1090 Proxy |
GroupMuddyWater | MuddyWater has used NordVPN to proxy phishing emails, making them appear to originate from France. |
| T1090.002 External Proxy |
GroupMuddyWater | MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data. |
| T1102.002 Bidirectional Communication |
GroupMuddyWater | MuddyWater has used web services including OneHub to distribute remote access tools. |
| T1104 Multi-Stage Channels |
GroupMuddyWater | MuddyWater has used one C2 to obtain enumeration scripts and monitor web logs, but a different C2 to send data back. |
| T1105 Ingress Tool Transfer |
GroupMuddyWater | MuddyWater has used malware that can upload additional files to the victim’s machine. MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data. |
| T1113 Screen Capture |
GroupMuddyWater | MuddyWater has used malware that can capture screenshots of the victim’s machine. |
| T1132.001 Standard Encoding |
GroupMuddyWater | MuddyWater has used tools to encode C2 communications including Base64 encoding. |
| T1137.001 Office Template Macros |
GroupMuddyWater | MuddyWater has used a Word Template, Normal.dotm, for persistence. |
| T1140 Deobfuscate/Decode Files or Information |
GroupMuddyWater | MuddyWater has decoded base64-encoded PowerShell, JavaScript, and VBScript. |
| T1190 Exploit Public-Facing Application |
GroupMuddyWater | MuddyWater has exploited the Microsoft Exchange memory corruption vulnerability (CVE-2020-0688). |
| T1203 Exploitation for Client Execution |
GroupMuddyWater | MuddyWater has exploited the Office vulnerability CVE-2017-0199 for execution. |
| T1204.001 Malicious Link |
GroupMuddyWater | MuddyWater has distributed URLs in phishing e-mails that link to lure documents. |
| T1204.002 Malicious File |
GroupMuddyWater | MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1204.004 Malicious Copy and Paste |
GroupMuddyWater | MuddyWater has leveraged ClickFix type tactics enticing victims to copy and paste malicious PowerShell code. |
| T1210 Exploitation of Remote Services |
GroupMuddyWater | MuddyWater has exploited the Microsoft Netlogon vulnerability (CVE-2020-1472). |
| T1218.003 CMSTP |
GroupMuddyWater | MuddyWater has used CMSTP.exe and a malicious INF to execute its POWERSTATS payload. |
| T1218.005 Mshta |
GroupMuddyWater | MuddyWater has used mshta.exe to execute its POWERSTATS payload and to pass a PowerShell one-liner for execution. |
| T1218.011 Rundll32 |
GroupMuddyWater | MuddyWater has used malware that leveraged rundll32.exe in a Registry Run key to execute a .dll. |
| T1219.002 Remote Desktop Software |
GroupMuddyWater | MuddyWater has leveraged RMM solutions including ScreenConnect, AteraAgent, SimpleHelp, Action1, Level, and PDQ to facilitate follow-on actions within compromised hosts to include data exfiltration. |
| T1518 Software Discovery |
GroupMuddyWater | MuddyWater has used a PowerShell backdoor to check for Skype connectivity on the target machine. |
| T1518.001 Security Software Discovery |
GroupMuddyWater | MuddyWater has used malware to check running processes against a hard-coded list of security tools often used by malware researchers. |
| T1534 Internal Spearphishing |
GroupMuddyWater | MuddyWater has used compromised mailboxes within target organizations to send spearphishing emails. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMuddyWater | MuddyWater has added Registry Run key |
| T1548.002 Bypass User Account Control |
GroupMuddyWater | MuddyWater uses various techniques to bypass UAC. |
| T1552.001 Credentials In Files |
GroupMuddyWater | MuddyWater has run a tool that steals passwords saved in victim email. |
| T1555 Credentials from Password Stores |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne and other tools, including by dumping passwords saved in victim email. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.