ATT&CKReferencesDHS CISA AA22-055A MuddyWater February 2022

DHS CISA AA22-055A MuddyWater February 2022

FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software4

Campaigns0

None recorded.

Procedure examples38

TechniqueUsed byProcedure example
T1001.001
Junk Data
MalwareMori

Mori has obfuscated the FML.dll with 200MB of junk data.

T1005
Data from Local System
MalwareSTARWHALE

STARWHALE can collect data from an infected local host.

T1012
Query Registry
MalwareMori

Mori can read data from the Registry including from `HKLM\Software\NFC\IPA` and
`HKLM\Software\NFC\`.

T1016
System Network Configuration Discovery
MalwareSTARWHALE

STARWHALE has the ability to collect the IP address of an infected host.

T1027.013
Encrypted/Encoded File
MalwareSTARWHALE

STARWHALE has been obfuscated with hex-encoded strings.

T1033
System Owner/User Discovery
MalwareSTARWHALE

STARWHALE can gather the username from an infected host.

T1036
Masquerading
MalwarePowGoop

PowGoop has disguised a PowerShell script as a .dat file (goopdate.dat).

T1036.005
Match Legitimate Resource Name or Location
MalwarePowGoop

PowGoop has used a DLL named Goopdate.dll to impersonate a legitimate Google update file.

T1041
Exfiltration Over C2 Channel
MalwareSTARWHALE

STARWHALE can exfiltrate collected data to its C2 servers.

T1047
Windows Management Instrumentation
GroupMuddyWater

MuddyWater has used malware that leveraged WMI for execution and querying host information.

T1059.001
PowerShell
MalwarePowGoop

PowGoop has the ability to use PowerShell scripts to execute commands.

T1059.001
PowerShell
GroupMuddyWater

MuddyWater has used PowerShell for execution.

T1059.001
PowerShell
MalwarePOWERSTATS

POWERSTATS uses PowerShell for obfuscation and execution.

T1059.007
JavaScript
GroupMuddyWater

MuddyWater has used JavaScript files to execute its POWERSTATS payload.

T1070.004
File Deletion
MalwareMori

Mori can delete its DLL file and related files by Registry value.

T1071.001
Web Protocols
MalwareSTARWHALE

STARWHALE has the ability to contact actor-controlled C2 servers via HTTP.

T1071.001
Web Protocols
MalwareMori

Mori can communicate using HTTP over IPv4 or IPv6 depending on a flag set.

T1071.001
Web Protocols
MalwareSmall Sieve

Small Sieve can contact actor-controlled C2 servers by using the Telegram API over HTTPS.

T1071.004
DNS
MalwareMori

Mori can use DNS tunneling to communicate with C2.

T1082
System Information Discovery
MalwareSTARWHALE

STARWHALE can gather the computer name of an infected host.

T1112
Modify Registry
MalwareMori

Mori can write data to `HKLM\Software\NFC\IPA` and `HKLM\Software\NFC\` and delete Registry values.

T1132.001
Standard Encoding
MalwareSTARWHALE

STARWHALE has the ability to hex-encode collected data from an infected host.

T1132.001
Standard Encoding
MalwareMori

Mori can use Base64 encoded JSON libraries used in C2.

T1132.002
Non-Standard Encoding
MalwareSmall Sieve

Small Sieve can use a custom hex byte swapping encoding scheme to obfuscate tasking traffic.

T1140
Deobfuscate/Decode Files or Information
MalwareMori

Mori can resolve networking APIs from strings that are ADD-encrypted.

T1140
Deobfuscate/Decode Files or Information
MalwarePowGoop

PowGoop can decrypt PowerShell scripts for execution.

T1190
Exploit Public-Facing Application
GroupMuddyWater

MuddyWater has exploited the Microsoft Exchange memory corruption vulnerability (CVE-2020-0688).

T1204.002
Malicious File
GroupMuddyWater

MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1204.002
Malicious File
MalwareSTARWHALE

STARWHALE has relied on victims opening a malicious Excel file for execution.

T1210
Exploitation of Remote Services
GroupMuddyWater

MuddyWater has exploited the Microsoft Netlogon vulnerability (CVE-2020-1472).

T1218.010
Regsvr32
MalwareMori

Mori can use `regsvr32.exe` for DLL execution.

T1547.001
Registry Run Keys / Startup Folder
MalwareSTARWHALE

STARWHALE can establish persistence by installing itself in the startup folder, whereas the GO variant has created a `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OutlookM` registry key.

T1559.001
Component Object Model
GroupMuddyWater

MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook.

T1566.001
Spearphishing Attachment
GroupMuddyWater

MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage.

T1573
Encrypted Channel
MalwarePowGoop

PowGoop can receive encrypted commands from C2.

T1573.002
Asymmetric Cryptography
MalwareSmall Sieve

Small Sieve can use SSL/TLS for its HTTPS Telegram Bot API-based C2 channel.

T1574.001
DLL
GroupMuddyWater

MuddyWater maintains persistence on victim networks through side-loading dlls to trick legitimate programs into running malware.

T1574.001
DLL
MalwarePowGoop

PowGoop can side-load `Goopdate.dll` into `GoogleUpdate.exe`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.