ClearSky Cyber Security. (2018, November). MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign. Retrieved November 29, 2018.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.003 Steganography |
GroupMuddyWater | MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg. |
| T1027.004 Compile After Delivery |
GroupMuddyWater | MuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code. |
| T1027.010 Command Obfuscation |
MalwarePOWERSTATS | POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation |
| T1036.004 Masquerade Task or Service |
MalwarePOWERSTATS | POWERSTATS has created a scheduled task named "MicrosoftEdge" to establish persistence. |
| T1047 Windows Management Instrumentation |
MalwarePOWERSTATS | POWERSTATS can use WMI queries to retrieve data from compromised hosts. |
| T1047 Windows Management Instrumentation |
GroupMuddyWater | MuddyWater has used malware that leveraged WMI for execution and querying host information. |
| T1053.005 Scheduled Task |
MalwarePOWERSTATS | POWERSTATS has established persistence through a scheduled task using the command |
| T1059.001 PowerShell |
MalwarePOWERSTATS | POWERSTATS uses PowerShell for obfuscation and execution. |
| T1059.001 PowerShell |
GroupMuddyWater | MuddyWater has used PowerShell for execution. ClearSky MuddyWater Nov 2018DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018MuddyWater TrendMicro June 2018NaumaanProofpoint_GlobalClickFix_April2025Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Symantec MuddyWater Dec 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021 |
| T1059.005 Visual Basic |
GroupMuddyWater | MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros. |
| T1059.005 Visual Basic |
MalwarePOWERSTATS | POWERSTATS can use VBScript (VBE) code for execution. |
| T1059.007 JavaScript |
GroupMuddyWater | MuddyWater has used JavaScript files to execute its POWERSTATS payload. |
| T1059.007 JavaScript |
MalwarePOWERSTATS | POWERSTATS can use JavaScript code for execution. |
| T1105 Ingress Tool Transfer |
GroupMuddyWater | MuddyWater has used malware that can upload additional files to the victim’s machine. MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data. |
| T1140 Deobfuscate/Decode Files or Information |
GroupMuddyWater | MuddyWater has decoded base64-encoded PowerShell, JavaScript, and VBScript. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePOWERSTATS | POWERSTATS can deobfuscate the main backdoor code. |
| T1548.002 Bypass User Account Control |
GroupMuddyWater | MuddyWater uses various techniques to bypass UAC. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.