ATT&CKReferencesTrend Micro Muddy Water March 2021

Trend Micro Muddy Water March 2021

Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples33

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupMuddyWater

MuddyWater has performed credential dumping with Mimikatz and procdump64.exe.

T1005
Data from Local System
ToolOut1

Out1 can copy files and Registry data from compromised hosts.

T1027
Obfuscated Files or Information
ToolOut1

Out1 has the ability to encode data.

T1027.010
Command Obfuscation
GroupMuddyWater

MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands.

T1033
System Owner/User Discovery
GroupMuddyWater

MuddyWater has used malware that can collect the victim’s username.

T1049
System Network Connections Discovery
GroupMuddyWater

MuddyWater has used a PowerShell backdoor to check for Skype connections on the target machine.

T1059.001
PowerShell
GroupMuddyWater

MuddyWater has used PowerShell for execution.

T1059.003
Windows Command Shell
ToolOut1

Out1 can use native command line for execution.

T1059.005
Visual Basic
GroupMuddyWater

MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros.

T1059.006
Python
GroupMuddyWater

MuddyWater has developed tools in Python including Out1.

T1071.001
Web Protocols
ToolOut1

Out1 can use HTTP and HTTPS in communications with remote hosts.

T1071.001
Web Protocols
GroupMuddyWater

MuddyWater has used HTTP for C2 communications.

T1082
System Information Discovery
GroupMuddyWater

MuddyWater has used malware that can collect the victim’s OS version and machine name.

T1083
File and Directory Discovery
ToolRemoteUtilities

RemoteUtilities can enumerate files and directories on a target machine.

T1087.002
Domain Account
GroupMuddyWater

MuddyWater has used cmd.exe net user /domain to enumerate domain users.

T1090.002
External Proxy
GroupMuddyWater

MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data.

T1105
Ingress Tool Transfer
GroupMuddyWater

MuddyWater has used malware that can upload additional files to the victim’s machine. MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data.

T1105
Ingress Tool Transfer
ToolRemoteUtilities

RemoteUtilities can upload and download files to and from a target machine.

T1113
Screen Capture
ToolRemoteUtilities

RemoteUtilities can take screenshots on a compromised host.

T1114.001
Local Email Collection
ToolOut1

Out1 can parse e-mails on a target machine.

T1132.001
Standard Encoding
GroupMuddyWater

MuddyWater has used tools to encode C2 communications including Base64 encoding.

T1204.001
Malicious Link
GroupMuddyWater

MuddyWater has distributed URLs in phishing e-mails that link to lure documents.

T1204.002
Malicious File
GroupMuddyWater

MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1218.007
Msiexec
ToolRemoteUtilities

RemoteUtilities can use Msiexec to install a service.

T1219.002
Remote Desktop Software
GroupMuddyWater

MuddyWater has leveraged RMM solutions including ScreenConnect, AteraAgent, SimpleHelp, Action1, Level, and PDQ to facilitate follow-on actions within compromised hosts to include data exfiltration.

T1518
Software Discovery
GroupMuddyWater

MuddyWater has used a PowerShell backdoor to check for Skype connectivity on the target machine.

T1547.001
Registry Run Keys / Startup Folder
GroupMuddyWater

MuddyWater has added Registry Run key KCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemTextEncoding to establish persistence.

T1555
Credentials from Password Stores
GroupMuddyWater

MuddyWater has performed credential dumping with LaZagne and other tools, including by dumping passwords saved in victim email.

T1555.003
Credentials from Web Browsers
GroupMuddyWater

MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers.

T1566.001
Spearphishing Attachment
GroupMuddyWater

MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage.

T1566.002
Spearphishing Link
GroupMuddyWater

MuddyWater has sent targeted spearphishing e-mails with malicious links.

T1583.006
Web Services
GroupMuddyWater

MuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools.

T1685
Disable or Modify Tools
GroupMuddyWater

MuddyWater can disable the system's local proxy settings.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.