Ctrl-Alt-Intel. (2026, March 4). MuddyWater Exposed: Inside an Iranian APT operation . Retrieved April 6, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareTsundere Botnet | Tsundere Botnet’s loader contained AES-CBC/PKCS7 encrypted blobs, which were descrypted and written to disk. |
| T1059.001 PowerShell |
MalwareTsundere Botnet | Tsundere Botnet has been distributed via a PowerShell script. |
| T1071.001 Web Protocols |
MalwareTsundere Botnet | Tsundere Botnet has obtained the WebSocket C2 address by making remote procedure call (RPC) APIs to Ethereum blockchain nodes. |
| T1102.001 Dead Drop Resolver |
MalwareTsundere Botnet | Tsundere Botnet has obtained the C2 address from Ethereum blockchain nodes. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTsundere Botnet | Tsundere Botnet’s loader has decrypted obfuscated JavaScript files using the AES-256 CBC algorithm, a build-specific key, and initialization vector. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTsundere Botnet | Tsundere Botnet has created a value in the `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` Registry key, ensuring that it is run at login. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.