ATT&CKReferencesClearSky MuddyWater Nov 2018

ClearSky MuddyWater Nov 2018

ClearSky Cyber Security. (2018, November). MuddyWater Operations in Lebanon and Oman: Using an Israeli compromised domain for a two-stage campaign. Retrieved November 29, 2018.

Open the source

Techniques1

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1027.003
Steganography
GroupMuddyWater

MuddyWater has stored obfuscated JavaScript code in an image file named temp.jpg.

T1027.004
Compile After Delivery
GroupMuddyWater

MuddyWater has used the .NET csc.exe tool to compile executables from downloaded C# code.

T1027.010
Command Obfuscation
MalwarePOWERSTATS

POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation

T1036.004
Masquerade Task or Service
MalwarePOWERSTATS

POWERSTATS has created a scheduled task named "MicrosoftEdge" to establish persistence.

T1047
Windows Management Instrumentation
MalwarePOWERSTATS

POWERSTATS can use WMI queries to retrieve data from compromised hosts.

T1047
Windows Management Instrumentation
GroupMuddyWater

MuddyWater has used malware that leveraged WMI for execution and querying host information.

T1053.005
Scheduled Task
MalwarePOWERSTATS

POWERSTATS has established persistence through a scheduled task using the command ”C:\Windows\system32\schtasks.exe” /Create /F /SC DAILY /ST 12:00 /TN MicrosoftEdge /TR “c:\Windows\system32\wscript.exe C:\Windows\temp\Windows.vbe”.

T1059.001
PowerShell
MalwarePOWERSTATS

POWERSTATS uses PowerShell for obfuscation and execution.

T1059.001
PowerShell
GroupMuddyWater

MuddyWater has used PowerShell for execution.

T1059.005
Visual Basic
GroupMuddyWater

MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros.

T1059.005
Visual Basic
MalwarePOWERSTATS

POWERSTATS can use VBScript (VBE) code for execution.

T1059.007
JavaScript
GroupMuddyWater

MuddyWater has used JavaScript files to execute its POWERSTATS payload.

T1059.007
JavaScript
MalwarePOWERSTATS

POWERSTATS can use JavaScript code for execution.

T1105
Ingress Tool Transfer
GroupMuddyWater

MuddyWater has used malware that can upload additional files to the victim’s machine. MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data.

T1140
Deobfuscate/Decode Files or Information
GroupMuddyWater

MuddyWater has decoded base64-encoded PowerShell, JavaScript, and VBScript.

T1140
Deobfuscate/Decode Files or Information
MalwarePOWERSTATS

POWERSTATS can deobfuscate the main backdoor code.

T1548.002
Bypass User Account Control
GroupMuddyWater

MuddyWater uses various techniques to bypass UAC.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.