ATT&CKReferencesSymantec MuddyWater Dec 2018

Symantec MuddyWater Dec 2018

Symantec DeepSight Adversary Intelligence Team. (2018, December 10). Seedworm: Group Compromises Government Agencies, Oil & Gas, NGOs, Telecoms, and IT Firms. Retrieved December 14, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupMuddyWater

MuddyWater has performed credential dumping with Mimikatz and procdump64.exe.

T1003.004
LSA Secrets
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne.

T1003.005
Cached Domain Credentials
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne.

T1059.001
PowerShell
GroupMuddyWater

MuddyWater has used PowerShell for execution.

T1059.003
Windows Command Shell
GroupMuddyWater

MuddyWater has used a custom tool for creating reverse shells.

T1059.005
Visual Basic
GroupMuddyWater

MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros.

T1090.002
External Proxy
GroupMuddyWater

MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data.

T1552.001
Credentials In Files
GroupMuddyWater

MuddyWater has run a tool that steals passwords saved in victim email.

T1555
Credentials from Password Stores
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne and other tools, including by dumping passwords saved in victim email.

T1555.003
Credentials from Web Browsers
GroupMuddyWater

MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers.

T1560.001
Archive via Utility
GroupMuddyWater

MuddyWater has used the native Windows cabinet creation tool, makecab.exe, likely to compress stolen data to be uploaded.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.