Symantec DeepSight Adversary Intelligence Team. (2018, December 10). Seedworm: Group Compromises Government Agencies, Oil & Gas, NGOs, Telecoms, and IT Firms. Retrieved December 14, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupMuddyWater | MuddyWater has performed credential dumping with Mimikatz and procdump64.exe. |
| T1003.004 LSA Secrets |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne. |
| T1003.005 Cached Domain Credentials |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne. |
| T1059.001 PowerShell |
GroupMuddyWater | MuddyWater has used PowerShell for execution. ClearSky MuddyWater Nov 2018DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018MuddyWater TrendMicro June 2018NaumaanProofpoint_GlobalClickFix_April2025Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Symantec MuddyWater Dec 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021 |
| T1059.003 Windows Command Shell |
GroupMuddyWater | MuddyWater has used a custom tool for creating reverse shells. |
| T1059.005 Visual Basic |
GroupMuddyWater | MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros. |
| T1090.002 External Proxy |
GroupMuddyWater | MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data. |
| T1552.001 Credentials In Files |
GroupMuddyWater | MuddyWater has run a tool that steals passwords saved in victim email. |
| T1555 Credentials from Password Stores |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne and other tools, including by dumping passwords saved in victim email. |
| T1555.003 Credentials from Web Browsers |
GroupMuddyWater | MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers. |
| T1560.001 Archive via Utility |
GroupMuddyWater | MuddyWater has used the native Windows cabinet creation tool, makecab.exe, likely to compress stolen data to be uploaded. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.