ATT&CKReferencesFireEye MuddyWater Mar 2018

FireEye MuddyWater Mar 2018

Singh, S. et al.. (2018, March 13). Iranian Threat Group Updates Tactics, Techniques and Procedures in Spear Phishing Campaign. Retrieved April 11, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwarePOWERSTATS

POWERSTATS can upload files from compromised hosts.

T1016
System Network Configuration Discovery
MalwarePOWERSTATS

POWERSTATS can retrieve IP, network adapter configuration information, and domain from compromised hosts.

T1027.010
Command Obfuscation
GroupMuddyWater

MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands.

T1027.010
Command Obfuscation
MalwarePOWERSTATS

POWERSTATS uses character replacement, PowerShell environment variables, and XOR encoding to obfuscate code. POWERSTATS's backdoor code is a multi-layer obfuscated, encoded, and compressed blob. POWERSTATS has used PowerShell code with custom string obfuscation

T1029
Scheduled Transfer
MalwarePOWERSTATS

POWERSTATS can sleep for a given number of seconds.

T1036.005
Match Legitimate Resource Name or Location
GroupMuddyWater

MuddyWater has disguised malicious executables and used filenames and Registry key names associated with Windows Defender.

T1047
Windows Management Instrumentation
MalwarePOWERSTATS

POWERSTATS can use WMI queries to retrieve data from compromised hosts.

T1059.001
PowerShell
GroupMuddyWater

MuddyWater has used PowerShell for execution.

T1059.005
Visual Basic
GroupMuddyWater

MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros.

T1059.007
JavaScript
GroupMuddyWater

MuddyWater has used JavaScript files to execute its POWERSTATS payload.

T1070.004
File Deletion
MalwarePOWERSTATS

POWERSTATS can delete all files on the C:\, D:\, E:\ and, F:\ drives using PowerShell Remove-Item commands.

T1082
System Information Discovery
MalwarePOWERSTATS

POWERSTATS can retrieve OS name/architecture and computer/domain name information from compromised hosts.

T1087.001
Local Account
MalwarePOWERSTATS

POWERSTATS can retrieve usernames from compromised hosts.

T1090.002
External Proxy
MalwarePOWERSTATS

POWERSTATS has connected to C2 servers through proxies.

T1105
Ingress Tool Transfer
MalwarePOWERSTATS

POWERSTATS can retrieve and execute additional PowerShell payloads from the C2 server.

T1113
Screen Capture
MalwarePOWERSTATS

POWERSTATS can retrieve screenshots from compromised hosts.

T1140
Deobfuscate/Decode Files or Information
GroupMuddyWater

MuddyWater has decoded base64-encoded PowerShell, JavaScript, and VBScript.

T1204.002
Malicious File
GroupMuddyWater

MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1218.003
CMSTP
GroupMuddyWater

MuddyWater has used CMSTP.exe and a malicious INF to execute its POWERSTATS payload.

T1218.005
Mshta
GroupMuddyWater

MuddyWater has used mshta.exe to execute its POWERSTATS payload and to pass a PowerShell one-liner for execution.

T1218.005
Mshta
MalwarePOWERSTATS

POWERSTATS can use Mshta.exe to execute additional payloads on compromised hosts.

T1518.001
Security Software Discovery
MalwarePOWERSTATS

POWERSTATS has detected security tools.

T1547.001
Registry Run Keys / Startup Folder
GroupMuddyWater

MuddyWater has added Registry Run key KCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemTextEncoding to establish persistence.

T1559.001
Component Object Model
MalwarePOWERSTATS

POWERSTATS can use DCOM (targeting the 127.0.0.1 loopback address) to execute additional payloads on compromised hosts.

T1559.002
Dynamic Data Exchange
MalwarePOWERSTATS

POWERSTATS can use DDE to execute additional payloads on compromised hosts.

T1566.001
Spearphishing Attachment
GroupMuddyWater

MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage.

T1573.002
Asymmetric Cryptography
MalwarePOWERSTATS

POWERSTATS has encrypted C2 traffic with RSA.

T1685
Disable or Modify Tools
MalwarePOWERSTATS

POWERSTATS can disable Microsoft Office Protected View by changing Registry keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.