ATT&CKReferencesUnit 42 MuddyWater Nov 2017

Unit 42 MuddyWater Nov 2017

Lancaster, T.. (2017, November 14). Muddying the Water: Targeted Attacks in the Middle East. Retrieved March 15, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupMuddyWater

MuddyWater has performed credential dumping with Mimikatz and procdump64.exe.

T1003.004
LSA Secrets
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne.

T1003.005
Cached Domain Credentials
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne.

T1027.010
Command Obfuscation
GroupMuddyWater

MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands.

T1059.001
PowerShell
MalwarePOWERSTATS

POWERSTATS uses PowerShell for obfuscation and execution.

T1132.001
Standard Encoding
MalwarePOWERSTATS

POWERSTATS encoded C2 traffic with base64.

T1204.002
Malicious File
GroupMuddyWater

MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1555
Credentials from Password Stores
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne and other tools, including by dumping passwords saved in victim email.

T1566.001
Spearphishing Attachment
GroupMuddyWater

MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.