FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.001 Junk Data |
MalwareMori | Mori has obfuscated the FML.dll with 200MB of junk data. |
| T1005 Data from Local System |
MalwareSTARWHALE | STARWHALE can collect data from an infected local host. |
| T1012 Query Registry |
MalwareMori | Mori can read data from the Registry including from `HKLM\Software\NFC\IPA` and |
| T1016 System Network Configuration Discovery |
MalwareSTARWHALE | STARWHALE has the ability to collect the IP address of an infected host. |
| T1027.013 Encrypted/Encoded File |
MalwareSTARWHALE | STARWHALE has been obfuscated with hex-encoded strings. |
| T1033 System Owner/User Discovery |
MalwareSTARWHALE | STARWHALE can gather the username from an infected host. |
| T1036 Masquerading |
MalwarePowGoop | PowGoop has disguised a PowerShell script as a .dat file (goopdate.dat). |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePowGoop | PowGoop has used a DLL named Goopdate.dll to impersonate a legitimate Google update file. |
| T1041 Exfiltration Over C2 Channel |
MalwareSTARWHALE | STARWHALE can exfiltrate collected data to its C2 servers. |
| T1047 Windows Management Instrumentation |
GroupMuddyWater | MuddyWater has used malware that leveraged WMI for execution and querying host information. |
| T1059.001 PowerShell |
MalwarePowGoop | PowGoop has the ability to use PowerShell scripts to execute commands. |
| T1059.001 PowerShell |
GroupMuddyWater | MuddyWater has used PowerShell for execution. ClearSky MuddyWater Nov 2018DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018MuddyWater TrendMicro June 2018NaumaanProofpoint_GlobalClickFix_April2025Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Symantec MuddyWater Dec 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021 |
| T1059.001 PowerShell |
MalwarePOWERSTATS | POWERSTATS uses PowerShell for obfuscation and execution. |
| T1059.007 JavaScript |
GroupMuddyWater | MuddyWater has used JavaScript files to execute its POWERSTATS payload. |
| T1070.004 File Deletion |
MalwareMori | Mori can delete its DLL file and related files by Registry value. |
| T1071.001 Web Protocols |
MalwareSTARWHALE | STARWHALE has the ability to contact actor-controlled C2 servers via HTTP. |
| T1071.001 Web Protocols |
MalwareMori | Mori can communicate using HTTP over IPv4 or IPv6 depending on a flag set. |
| T1071.001 Web Protocols |
MalwareSmall Sieve | Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS. |
| T1071.004 DNS |
MalwareMori | Mori can use DNS tunneling to communicate with C2. |
| T1082 System Information Discovery |
MalwareSTARWHALE | STARWHALE can gather the computer name of an infected host. |
| T1112 Modify Registry |
MalwareMori | Mori can write data to `HKLM\Software\NFC\IPA` and `HKLM\Software\NFC\` and delete Registry values. |
| T1132.001 Standard Encoding |
MalwareSTARWHALE | STARWHALE has the ability to hex-encode collected data from an infected host. |
| T1132.001 Standard Encoding |
MalwareMori | Mori can use Base64 encoded JSON libraries used in C2. |
| T1132.002 Non-Standard Encoding |
MalwareSmall Sieve | Small Sieve can use a custom hex byte swapping encoding scheme to obfuscate tasking traffic. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMori | Mori can resolve networking APIs from strings that are ADD-encrypted. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePowGoop | PowGoop can decrypt PowerShell scripts for execution. |
| T1190 Exploit Public-Facing Application |
GroupMuddyWater | MuddyWater has exploited the Microsoft Exchange memory corruption vulnerability (CVE-2020-0688). |
| T1204.002 Malicious File |
GroupMuddyWater | MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1204.002 Malicious File |
MalwareSTARWHALE | STARWHALE has relied on victims opening a malicious Excel file for execution. |
| T1210 Exploitation of Remote Services |
GroupMuddyWater | MuddyWater has exploited the Microsoft Netlogon vulnerability (CVE-2020-1472). |
| T1218.010 Regsvr32 |
MalwareMori | Mori can use `regsvr32.exe` for DLL execution. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareSTARWHALE | STARWHALE can establish persistence by installing itself in the startup folder, whereas the GO variant has created a `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OutlookM` registry key. |
| T1559.001 Component Object Model |
GroupMuddyWater | MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook. |
| T1566.001 Spearphishing Attachment |
GroupMuddyWater | MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022ESET_MuddyWater_Dec2025FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024SOCRadar_MuddyWaterDindoor_Mar2026Securelist MuddyWater Oct 2018Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1573 Encrypted Channel |
MalwarePowGoop | PowGoop can receive encrypted commands from C2. |
| T1573.002 Asymmetric Cryptography |
MalwareSmall Sieve | Small Sieve can use SSL/TLS for its HTTPS Telegram Bot API-based C2 channel. |
| T1574.001 DLL |
GroupMuddyWater | MuddyWater maintains persistence on victim networks through side-loading dlls to trick legitimate programs into running malware. |
| T1574.001 DLL |
MalwarePowGoop | PowGoop can side-load `Goopdate.dll` into `GoogleUpdate.exe`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.