ATT&CKReferencesSOCRadar_MuddyWaterDindoor_Mar2026

SOCRadar_MuddyWaterDindoor_Mar2026

SOCRadar. (2026, March 9). MuddyWater Uses Dindoor Malware Targeting U.S. Networks. Retrieved March 12, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1566.001
Spearphishing Attachment
GroupMuddyWater

MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage.

T1567.002
Exfiltration to Cloud Storage
GroupMuddyWater

MuddyWater has attempted to exfiltrate data to Wasabi, a cloud storage service, using Rclone.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.