Mele, G. et al. (2021, February 10). Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies. Retrieved March 17, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
GroupMuddyWater | MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender. |
| T1059.001 PowerShell |
ToolConnectWise | ConnectWise can be used to execute PowerShell commands on target machines. |
| T1102.002 Bidirectional Communication |
GroupMuddyWater | MuddyWater has used web services including OneHub to distribute remote access tools. |
| T1113 Screen Capture |
ToolConnectWise | ConnectWise can take screenshots on remote hosts. |
| T1125 Video Capture |
ToolConnectWise | ConnectWise can record video on remote hosts. |
| T1204.001 Malicious Link |
GroupMuddyWater | MuddyWater has distributed URLs in phishing e-mails that link to lure documents. |
| T1204.002 Malicious File |
GroupMuddyWater | MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1219.002 Remote Desktop Software |
GroupMuddyWater | MuddyWater has leveraged RMM solutions including ScreenConnect, AteraAgent, SimpleHelp, Action1, Level, and PDQ to facilitate follow-on actions within compromised hosts to include data exfiltration. |
| T1566.001 Spearphishing Attachment |
GroupMuddyWater | MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022ESET_MuddyWater_Dec2025FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024SOCRadar_MuddyWaterDindoor_Mar2026Securelist MuddyWater Oct 2018Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1566.002 Spearphishing Link |
GroupMuddyWater | MuddyWater has sent targeted spearphishing e-mails with malicious links. |
| T1583.006 Web Services |
GroupMuddyWater | MuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools. |
| T1588.002 Tool |
GroupMuddyWater | MuddyWater has used legitimate tools ConnectWise, RemoteUtilities, and SimpleHelp to gain access to the target environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.