ATT&CKReferencesCloudSEK_RustyWater_Jan2026

CloudSEK_RustyWater_Jan2026

Awasthi, P. (2026, January 8). Reborn in Rust: Muddy Water Evolves Tooling with RustyWater Implant. Retrieved March 19, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareRustyWater

RustyWater has an obfuscated function (i.e. love_me__()) that dynamically reconstructs the string WScript.Shell using hard-coded ASCII values and the Chr() function.

T1027.013
Encrypted/Encoded File
MalwareRustyWater

RustyWater has encrypted all strings in the code using position independent XOR encryption.

T1033
System Owner/User Discovery
MalwareRustyWater

RustyWater has gathered the victim machine’s username.

T1036.005
Match Legitimate Resource Name or Location
MalwareRustyWater

RustyWater has used reddit.exe as its file name and a Cloudflare logo.

T1055.002
Portable Executable Injection
MalwareRustyWater

RustyWater has injected its shellcode into explorer.exe by allocating memory via `VirtualAllocEx`, then by writing the payload via `WriteProcessMemory`.

T1071.001
Web Protocols
MalwareRustyWater

RustyWater has used the Rust request library for HTTP C2 communication.

T1082
System Information Discovery
MalwareRustyWater

RustyWater has gathered the victim machine’s computer name.

T1087.002
Domain Account
MalwareRustyWater

RustyWater has gathered the domain membership of the victim machine’s user.

T1106
Native API
MalwareRustyWater

RustyWater has used `CreateObject` to instantiate a WScript.Shell Component Object Model (COM) object.  Additionally, RustyWater has used `VirtualAllocEx` and `WriteProcessMemory` to inject shellcode into explorer.exe.

T1132.001
Standard Encoding
MalwareRustyWater

RustyWater has encoded collected data with Base64.

T1140
Deobfuscate/Decode Files or Information
MalwareRustyWater

RustyWater has used the WriteHexToFile function to transform an embedded hex string to the payload CertificationKit.ini.

T1204.002
Malicious File
GroupMuddyWater

MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1204.002
Malicious File
MalwareRustyWater

RustyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1518.001
Security Software Discovery
MalwareRustyWater

RustyWater has attempted to detect more than 25 antivirus and EDR tools.

T1547.001
Registry Run Keys / Startup Folder
MalwareRustyWater

RustyWater has established persistence by adding `C:\ProgramData\CertificationKit.ini` to a Windows startup Registry key or to a Run or RunOnce Registry key.

T1559.001
Component Object Model
MalwareRustyWater

RustyWater has used a WScript.Shell COM object to execute the CertificationKit.ini file.

T1566.001
Spearphishing Attachment
MalwareRustyWater

RustyWater has sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primary payload for the next stage.

T1566.001
Spearphishing Attachment
GroupMuddyWater

MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage.

T1573.001
Symmetric Cryptography
MalwareRustyWater

RustyWater has encrypted encoded data with XOR before sending it to the C2 server.

T1622
Debugger Evasion
MalwareRustyWater

RustyWater has registered a Vectored Exception Handler (VEH) to catch debugging efforts.

T1678
Delay Execution
MalwareRustyWater

RustyWater has generated random sleep intervals between C2 communication.

T1684.001
Impersonation
GroupMuddyWater

MuddyWater has used support@microsoftonlines[.]com to send phishing emails that masqueraded as security updates from Microsoft. MuddyWater has also impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain info@tmcell.

T1684.001
Impersonation
MalwareRustyWater

RustyWater has impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain `info@tmcell`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.