ATT&CKReferencesTalos MuddyWater Jan 2022

Talos MuddyWater Jan 2022

Malhortra, A and Ventura, V. (2022, January 31). Iranian APT MuddyWater targets Turkish users via malicious PDFs, executables. Retrieved June 22, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupMuddyWater

MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands.

T1059.001
PowerShell
GroupMuddyWater

MuddyWater has used PowerShell for execution.

T1059.005
Visual Basic
GroupMuddyWater

MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros.

T1074.001
Local Data Staging
GroupMuddyWater

MuddyWater has stored a decoy PDF file within a victim's `%temp%` folder.

T1082
System Information Discovery
GroupMuddyWater

MuddyWater has used malware that can collect the victim’s OS version and machine name.

T1140
Deobfuscate/Decode Files or Information
GroupMuddyWater

MuddyWater has decoded base64-encoded PowerShell, JavaScript, and VBScript.

T1204.002
Malicious File
GroupMuddyWater

MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1547.001
Registry Run Keys / Startup Folder
GroupMuddyWater

MuddyWater has added Registry Run key KCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemTextEncoding to establish persistence.

T1573.001
Symmetric Cryptography
GroupMuddyWater

MuddyWater has used AES to encrypt C2 responses.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.