Awasthi, P. (2026, January 8). Reborn in Rust: Muddy Water Evolves Tooling with RustyWater Implant. Retrieved March 19, 2026.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareRustyWater | RustyWater has an obfuscated function (i.e. love_me__()) that dynamically reconstructs the string WScript.Shell using hard-coded ASCII values and the Chr() function. |
| T1027.013 Encrypted/Encoded File |
MalwareRustyWater | RustyWater has encrypted all strings in the code using position independent XOR encryption. |
| T1033 System Owner/User Discovery |
MalwareRustyWater | RustyWater has gathered the victim machine’s username. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRustyWater | RustyWater has used reddit.exe as its file name and a Cloudflare logo. |
| T1055.002 Portable Executable Injection |
MalwareRustyWater | RustyWater has injected its shellcode into explorer.exe by allocating memory via `VirtualAllocEx`, then by writing the payload via `WriteProcessMemory`. |
| T1071.001 Web Protocols |
MalwareRustyWater | RustyWater has used the Rust request library for HTTP C2 communication. |
| T1082 System Information Discovery |
MalwareRustyWater | RustyWater has gathered the victim machine’s computer name. |
| T1087.002 Domain Account |
MalwareRustyWater | RustyWater has gathered the domain membership of the victim machine’s user. |
| T1106 Native API |
MalwareRustyWater | RustyWater has used `CreateObject` to instantiate a WScript.Shell Component Object Model (COM) object. Additionally, RustyWater has used `VirtualAllocEx` and `WriteProcessMemory` to inject shellcode into explorer.exe. |
| T1132.001 Standard Encoding |
MalwareRustyWater | RustyWater has encoded collected data with Base64. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRustyWater | RustyWater has used the WriteHexToFile function to transform an embedded hex string to the payload CertificationKit.ini. |
| T1204.002 Malicious File |
GroupMuddyWater | MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1204.002 Malicious File |
MalwareRustyWater | RustyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. |
| T1518.001 Security Software Discovery |
MalwareRustyWater | RustyWater has attempted to detect more than 25 antivirus and EDR tools. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRustyWater | RustyWater has established persistence by adding `C:\ProgramData\CertificationKit.ini` to a Windows startup Registry key or to a Run or RunOnce Registry key. |
| T1559.001 Component Object Model |
MalwareRustyWater | RustyWater has used a WScript.Shell COM object to execute the CertificationKit.ini file. |
| T1566.001 Spearphishing Attachment |
MalwareRustyWater | RustyWater has sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primary payload for the next stage. |
| T1566.001 Spearphishing Attachment |
GroupMuddyWater | MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022ESET_MuddyWater_Dec2025FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024SOCRadar_MuddyWaterDindoor_Mar2026Securelist MuddyWater Oct 2018Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1573.001 Symmetric Cryptography |
MalwareRustyWater | RustyWater has encrypted encoded data with XOR before sending it to the C2 server. |
| T1622 Debugger Evasion |
MalwareRustyWater | RustyWater has registered a Vectored Exception Handler (VEH) to catch debugging efforts. |
| T1678 Delay Execution |
MalwareRustyWater | RustyWater has generated random sleep intervals between C2 communication. |
| T1684.001 Impersonation |
GroupMuddyWater | MuddyWater has used support@microsoftonlines[.]com to send phishing emails that masqueraded as security updates from Microsoft. MuddyWater has also impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain info@tmcell. |
| T1684.001 Impersonation |
MalwareRustyWater | RustyWater has impersonated TMCell (Altyn Asyr CJSC), the primary mobile operator in Turkmenistan, sending phishing emails with the email domain `info@tmcell`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.