ESET Research. (2025, December 2). MuddyWater: Snakes by the riverbank. Retrieved February 17, 2026.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareFooder | Fooder has stored its embedded payload in encrypted form within the binary, using a hardcoded key modified at runtime to produce the AES decryption key. |
| T1027.007 Dynamic API Resolution |
MalwareLP-Notes | LP-Notes has dynamically resolved API functions during the C runtime startup. |
| T1027.013 Encrypted/Encoded File |
MalwareLP-Notes | LP-Notes has used a custom addition-based function and a string stacking function for string encryption. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareFooder | Fooder has frequently masqueraded as the Snake game, using strings such as “Welcome to snake Game” and mutexes such as “SNAKE_G.” |
| T1041 Exfiltration Over C2 Channel |
MalwareMuddyViper | MuddyViper has uploaded files to the C2 server. Additionally, MuddyViper has the ability to upload the specified file in chunks with sleep time between each chunk. |
| T1053.005 Scheduled Task |
MalwareMuddyViper | MuddyViper has the ability to establish persistence by creating a scheduled task named ManageOnDriveUpdater to launch itself during system startup. |
| T1056.002 GUI Input Capture |
MalwareLP-Notes | LP-Notes has displayed a fake Windows Security dialog box to prompt for Windows credentials. |
| T1056.002 GUI Input Capture |
MalwareMuddyViper | MuddyViper has displayed a fake Windows Security dialog to gather credentials. |
| T1057 Process Discovery |
MalwareLP-Notes | LP-Notes has searched for the process taskhostw.exe. |
| T1057 Process Discovery |
MalwareMuddyViper | MuddyViper has the ability to collect running processes. |
| T1059 Command and Scripting Interpreter |
MalwareMuddyViper | MuddyViper has launched a reverse shell using a provided command line. |
| T1059.001 PowerShell |
MalwareLP-Notes | LP-Notes has been downloaded and executed by PowerShell’s`Invoke-WebRequest` and `Invoke-Expression` cmdlets. |
| T1059.001 PowerShell |
MalwareMuddyViper | MuddyViper has used PowerShell.exe to launch a reverse shell. |
| T1059.003 Windows Command Shell |
MalwareMuddyViper | MuddyViper has used cmd.exe to launch a reverse shell. |
| T1071.001 Web Protocols |
MalwareMuddyViper | MuddyViper has used HTTP GET requests over port 443 and with the WINHTTP_FLAG_SECURE set to SSL/TLS via the WinHTTP API. |
| T1074.001 Local Data Staging |
MalwareLP-Notes | LP-Notes has stored collected credentials in ` C:\Users\Public\Downloads\lp-notes.txt`. |
| T1078 Valid Accounts |
MalwareLP-Notes | LP-Notes has used stolen Windows credentials to log in as the users. |
| T1090.002 External Proxy |
GroupMuddyWater | MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data. |
| T1105 Ingress Tool Transfer |
MalwareMuddyViper | MuddyViper has the ability to download files from the C2 server. Additionally, MuddyViper has the ability to download a file in chunks with sleep time between each chunk. |
| T1106 Native API |
MalwareLP-Notes | LP-Notes has used the `ImpersonateLoggedOnUser` API to impersonate the security context of the taskhostw.exe process. Additionally, LP-Notes has also used the `CredUIPromptForWindowsCredentialsW` API to obtain Windows credentials. |
| T1106 Native API |
MalwareFooder | Fooder has used the WinCrypt API for payload decryption, `DuplicateTokenEx` to duplicate the token of a specified process, and `CreateProcessAsUserA` for payload execution. |
| T1106 Native API |
MalwareMuddyViper | MuddyViper has the ability to relaunch itself using the `CreateProcessW` API. |
| T1112 Modify Registry |
MalwareMuddyViper | MuddyViper has the ability to clear the Registry values in the Windows Startup folder that were previously set for persistence. |
| T1134.001 Token Impersonation/Theft |
MalwareFooder | Fooder has used the `DuplicateTokenEx` API to duplicate the token of a specified process, and `CreateProcessAsUserA` to execute its payload. |
| T1134.001 Token Impersonation/Theft |
MalwareLP-Notes | LP-Notes has impersonated the security context of the taskhostw.exe process via the `ImpersonateLoggedOnUser` API. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLP-Notes | LP-Notes has decrypted strings with lengths ranging from 15 to 19 characters using the same decryption key for each string. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMuddyViper | MuddyViper has decrypted the embedded HackBrowserData tool prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFooder | Fooder has decrypted payloads using the WinCrypt API and the AES key. |
| T1518.001 Security Software Discovery |
MalwareMuddyViper | MuddyViper has the ability to check for a specified list of security tools in the compromised environment. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMuddyViper | MuddyViper has the ability to establish persistence by configuring its installation directory as a Windows Startup folder by setting the following Registry values to `%APPDATALOCAL%\Microsoft\Windows\PPBCompatCache\ManagerCache`: `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup`. |
| T1560 Archive Collected Data |
MalwareMuddyViper | MuddyViper has archived collected web browser data into a file named CacheDump.zip. |
| T1560 Archive Collected Data |
MalwareLP-Notes | LP-Notes has encrypted collected credentials using AES-CBC from the CNG API and the key ED15C8344B45DAED1E0578F8BC1A32411812C61F4CB45D89B107287DE0E09FFC |
| T1566.001 Spearphishing Attachment |
GroupMuddyWater | MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022ESET_MuddyWater_Dec2025FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024SOCRadar_MuddyWaterDindoor_Mar2026Securelist MuddyWater Oct 2018Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1573.001 Symmetric Cryptography |
MalwareMuddyViper | MuddyViper has the ability to encrypt C2 communication using AES-CBC using the CNG API, the key `0608101047106453101617106423101013101012101083109710108585106969`, and the initialization vector `0`. |
| T1583.006 Web Services |
GroupMuddyWater | MuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools. |
| T1588.002 Tool |
GroupMuddyWater | MuddyWater has used legitimate tools ConnectWise, RemoteUtilities, and SimpleHelp to gain access to the target environment. |
| T1620 Reflective Code Loading |
MalwareFooder | Fooder has reflectively loaded a payload into memory. |
| T1620 Reflective Code Loading |
MalwareMuddyViper | MuddyViper has reflectively loaded the decrypted HackBrowserData tool in a new thread. |
| T1678 Delay Execution |
MalwareFooder | Fooder has used a custom delay function (`delayExecution(integer)`) and Sleep API calls (`Sleep(integer)`) to slow code execution. |
| T1678 Delay Execution |
MalwareMuddyViper | MuddyViper has the ability to sleep for a certain amount of time, with the default being one minute. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.