ATT&CKReferencesESET_MuddyWater_Dec2025

ESET_MuddyWater_Dec2025

ESET Research. (2025, December 2). MuddyWater: Snakes by the riverbank. Retrieved February 17, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples40

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareFooder

Fooder has stored its embedded payload in encrypted form within the binary, using a hardcoded key modified at runtime to produce the AES decryption key.

T1027.007
Dynamic API Resolution
MalwareLP-Notes

LP-Notes has dynamically resolved API functions during the C runtime startup.

T1027.013
Encrypted/Encoded File
MalwareLP-Notes

LP-Notes has used a custom addition-based function and a string stacking function for string encryption.

T1036.005
Match Legitimate Resource Name or Location
MalwareFooder

Fooder has frequently masqueraded as the Snake game, using strings such as “Welcome to snake Game” and mutexes such as “SNAKE_G.”

T1041
Exfiltration Over C2 Channel
MalwareMuddyViper

MuddyViper has uploaded files to the C2 server. Additionally, MuddyViper has the ability to upload the specified file in chunks with sleep time between each chunk.

T1053.005
Scheduled Task
MalwareMuddyViper

MuddyViper has the ability to establish persistence by creating a scheduled task named ManageOnDriveUpdater to launch itself during system startup.

T1056.002
GUI Input Capture
MalwareLP-Notes

LP-Notes has displayed a fake Windows Security dialog box to prompt for Windows credentials.

T1056.002
GUI Input Capture
MalwareMuddyViper

MuddyViper has displayed a fake Windows Security dialog to gather credentials.

T1057
Process Discovery
MalwareLP-Notes

LP-Notes has searched for the process taskhostw.exe.

T1057
Process Discovery
MalwareMuddyViper

MuddyViper has the ability to collect running processes.

T1059
Command and Scripting Interpreter
MalwareMuddyViper

MuddyViper has launched a reverse shell using a provided command line.

T1059.001
PowerShell
MalwareLP-Notes

LP-Notes has been downloaded and executed by PowerShell’s`Invoke-WebRequest` and `Invoke-Expression` cmdlets.

T1059.001
PowerShell
MalwareMuddyViper

MuddyViper has used PowerShell.exe to launch a reverse shell.

T1059.003
Windows Command Shell
MalwareMuddyViper

MuddyViper has used cmd.exe to launch a reverse shell.

T1071.001
Web Protocols
MalwareMuddyViper

MuddyViper has used HTTP GET requests over port 443 and with the WINHTTP_FLAG_SECURE set to SSL/TLS via the WinHTTP API.

T1074.001
Local Data Staging
MalwareLP-Notes

LP-Notes has stored collected credentials in ` C:\Users\Public\Downloads\lp-notes.txt`.

T1078
Valid Accounts
MalwareLP-Notes

LP-Notes has used stolen Windows credentials to log in as the users.

T1090.002
External Proxy
GroupMuddyWater

MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data.

T1105
Ingress Tool Transfer
MalwareMuddyViper

MuddyViper has the ability to download files from the C2 server. Additionally, MuddyViper has the ability to download a file in chunks with sleep time between each chunk.

T1106
Native API
MalwareLP-Notes

LP-Notes has used the `ImpersonateLoggedOnUser` API to impersonate the security context of the taskhostw.exe process. Additionally, LP-Notes has also used the `CredUIPromptForWindowsCredentialsW` API to obtain Windows credentials.

T1106
Native API
MalwareFooder

Fooder has used the WinCrypt API for payload decryption, `DuplicateTokenEx` to duplicate the token of a specified process, and `CreateProcessAsUserA` for payload execution.

T1106
Native API
MalwareMuddyViper

MuddyViper has the ability to relaunch itself using the `CreateProcessW` API.

T1112
Modify Registry
MalwareMuddyViper

MuddyViper has the ability to clear the Registry values in the Windows Startup folder that were previously set for persistence.

T1134.001
Token Impersonation/Theft
MalwareFooder

Fooder has used the `DuplicateTokenEx` API to duplicate the token of a specified process, and `CreateProcessAsUserA` to execute its payload.

T1134.001
Token Impersonation/Theft
MalwareLP-Notes

LP-Notes has impersonated the security context of the taskhostw.exe process via the `ImpersonateLoggedOnUser` API.

T1140
Deobfuscate/Decode Files or Information
MalwareLP-Notes

LP-Notes has decrypted strings with lengths ranging from 15 to 19 characters using the same decryption key for each string.

T1140
Deobfuscate/Decode Files or Information
MalwareMuddyViper

MuddyViper has decrypted the embedded HackBrowserData tool prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareFooder

Fooder has decrypted payloads using the WinCrypt API and the AES key.

T1518.001
Security Software Discovery
MalwareMuddyViper

MuddyViper has the ability to check for a specified list of security tools in the compromised environment.

T1547.001
Registry Run Keys / Startup Folder
MalwareMuddyViper

MuddyViper has the ability to establish persistence by configuring its installation directory as a Windows Startup folder by setting the following Registry values to `%APPDATALOCAL%\Microsoft\Windows\PPBCompatCache\ManagerCache`:  `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup`.

T1560
Archive Collected Data
MalwareMuddyViper

MuddyViper has archived collected web browser data into a file named CacheDump.zip.

T1560
Archive Collected Data
MalwareLP-Notes

LP-Notes has encrypted collected credentials using AES-CBC from the CNG API and the key ED15C8344B45DAED1E0578F8BC1A32411812C61F4CB45D89B107287DE0E09FFC
and the initialization vector 91A4E6F6D51DAEE773A8F00279792578.

T1566.001
Spearphishing Attachment
GroupMuddyWater

MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage.

T1573.001
Symmetric Cryptography
MalwareMuddyViper

MuddyViper has the ability to encrypt C2 communication using AES-CBC using the CNG API, the key `0608101047106453101617106423101013101012101083109710108585106969`, and the initialization vector `0`.

T1583.006
Web Services
GroupMuddyWater

MuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools.

T1588.002
Tool
GroupMuddyWater

MuddyWater has used legitimate tools ConnectWise, RemoteUtilities, and SimpleHelp to gain access to the target environment.

T1620
Reflective Code Loading
MalwareFooder

Fooder has reflectively loaded a payload into memory.

T1620
Reflective Code Loading
MalwareMuddyViper

MuddyViper has reflectively loaded the decrypted HackBrowserData tool in a new thread.

T1678
Delay Execution
MalwareFooder

Fooder has used a custom delay function (`delayExecution(integer)`) and Sleep API calls (`Sleep(integer)`) to slow code execution.

T1678
Delay Execution
MalwareMuddyViper

MuddyViper has the ability to sleep for a certain amount of time, with the default being one minute.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.