ATT&CKReferencesCAL_MuddyWater_Mar2026

CAL_MuddyWater_Mar2026

Ctrl-Alt-Intel. (2026, March 4). MuddyWater Exposed: Inside an Iranian APT operation . Retrieved April 6, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareTsundere Botnet

Tsundere Botnet’s loader contained AES-CBC/PKCS7 encrypted blobs, which were descrypted and written to disk.

T1059.001
PowerShell
MalwareTsundere Botnet

Tsundere Botnet has been distributed via a PowerShell script.

T1071.001
Web Protocols
MalwareTsundere Botnet

Tsundere Botnet has obtained the WebSocket C2 address by making remote procedure call (RPC) APIs to Ethereum blockchain nodes.

T1102.001
Dead Drop Resolver
MalwareTsundere Botnet

Tsundere Botnet has obtained the C2 address from Ethereum blockchain nodes.

T1140
Deobfuscate/Decode Files or Information
MalwareTsundere Botnet

Tsundere Botnet’s loader has decrypted obfuscated JavaScript files using the AES-256 CBC algorithm, a build-specific key, and initialization vector.

T1547.001
Registry Run Keys / Startup Folder
MalwareTsundere Botnet

Tsundere Botnet has created a value in the `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` Registry key, ensuring that it is run at login.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.