ATT&CKReferencesClearSky MuddyWater June 2019

ClearSky MuddyWater June 2019

ClearSky. (2019, June). Iranian APT group ‘MuddyWater’ Adds Exploits to Their Arsenal. Retrieved May 14, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupMuddyWater

MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands.

T1057
Process Discovery
GroupMuddyWater

MuddyWater has used malware to obtain a list of running processes on the system.

T1059.005
Visual Basic
GroupMuddyWater

MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros.

T1071.001
Web Protocols
GroupMuddyWater

MuddyWater has used HTTP for C2 communications.

T1132.001
Standard Encoding
GroupMuddyWater

MuddyWater has used tools to encode C2 communications including Base64 encoding.

T1203
Exploitation for Client Execution
GroupMuddyWater

MuddyWater has exploited the Office vulnerability CVE-2017-0199 for execution.

T1204.002
Malicious File
GroupMuddyWater

MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1559.001
Component Object Model
GroupMuddyWater

MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook.

T1566.001
Spearphishing Attachment
GroupMuddyWater

MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.