Singh, S. et al.. (2018, March 13). Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign. Retrieved April 11, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwarePOWERSTATS | POWERSTATS can upload files from compromised hosts. |
| T1016 System Network Configuration Discovery |
MalwarePOWERSTATS | POWERSTATS can retrieve IP, network adapter configuration information, and domain from compromised hosts. |
| T1027.010 Command Obfuscation |
GroupMuddyWater | MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands. |
| T1027.010 Command Obfuscation |
MalwarePOWERSTATS | POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation |
| T1029 Scheduled Transfer |
MalwarePOWERSTATS | POWERSTATS can sleep for a given number of seconds. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMuddyWater | MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender. |
| T1047 Windows Management Instrumentation |
MalwarePOWERSTATS | POWERSTATS can use WMI queries to retrieve data from compromised hosts. |
| T1059.001 PowerShell |
GroupMuddyWater | MuddyWater has used PowerShell for execution. ClearSky MuddyWater Nov 2018DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018MuddyWater TrendMicro June 2018NaumaanProofpoint_GlobalClickFix_April2025Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Symantec MuddyWater Dec 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021 |
| T1059.005 Visual Basic |
GroupMuddyWater | MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros. |
| T1059.007 JavaScript |
GroupMuddyWater | MuddyWater has used JavaScript files to execute its POWERSTATS payload. |
| T1070.004 File Deletion |
MalwarePOWERSTATS | POWERSTATS can delete all files on the C:\, D:\, E:\ and, F:\ drives using PowerShell Remove-Item commands. |
| T1082 System Information Discovery |
MalwarePOWERSTATS | POWERSTATS can retrieve OS name/architecture and computer/domain name information from compromised hosts. |
| T1087.001 Local Account |
MalwarePOWERSTATS | POWERSTATS can retrieve usernames from compromised hosts. |
| T1090.002 External Proxy |
MalwarePOWERSTATS | POWERSTATS has connected to C2 servers through proxies. |
| T1105 Ingress Tool Transfer |
MalwarePOWERSTATS | POWERSTATS can retrieve and execute additional PowerShell payloads from the C2 server. |
| T1113 Screen Capture |
MalwarePOWERSTATS | POWERSTATS can retrieve screenshots from compromised hosts. |
| T1140 Deobfuscate/Decode Files or Information |
GroupMuddyWater | MuddyWater has decoded base64-encoded PowerShell, JavaScript, and VBScript. |
| T1204.002 Malicious File |
GroupMuddyWater | MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1218.003 CMSTP |
GroupMuddyWater | MuddyWater has used CMSTP.exe and a malicious INF to execute its POWERSTATS payload. |
| T1218.005 Mshta |
GroupMuddyWater | MuddyWater has used mshta.exe to execute its POWERSTATS payload and to pass a PowerShell one-liner for execution. |
| T1218.005 Mshta |
MalwarePOWERSTATS | POWERSTATS can use Mshta.exe to execute additional payloads on compromised hosts. |
| T1518.001 Security Software Discovery |
MalwarePOWERSTATS | POWERSTATS has detected security tools. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMuddyWater | MuddyWater has added Registry Run key |
| T1559.001 Component Object Model |
MalwarePOWERSTATS | POWERSTATS can use DCOM (targeting the 127.0.0.1 loopback address) to execute additional payloads on compromised hosts. |
| T1559.002 Dynamic Data Exchange |
MalwarePOWERSTATS | POWERSTATS can use DDE to execute additional payloads on compromised hosts. |
| T1566.001 Spearphishing Attachment |
GroupMuddyWater | MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022ESET_MuddyWater_Dec2025FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024SOCRadar_MuddyWaterDindoor_Mar2026Securelist MuddyWater Oct 2018Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1573.002 Asymmetric Cryptography |
MalwarePOWERSTATS | POWERSTATS has encrypted C2 traffic with RSA. |
| T1685 Disable or Modify Tools |
MalwarePOWERSTATS | POWERSTATS can disable Microsoft Office Protected View by changing Registry keys. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.