Kaspersky Lab's Global Research & Analysis Team. (2018, October 10). MuddyWater expands operations. Retrieved November 2, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupMuddyWater | MuddyWater has used malware to collect the victim’s IP address and domain name. |
| T1027.010 Command Obfuscation |
GroupMuddyWater | MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands. |
| T1033 System Owner/User Discovery |
GroupMuddyWater | MuddyWater has used malware that can collect the victim’s username. |
| T1047 Windows Management Instrumentation |
GroupMuddyWater | MuddyWater has used malware that leveraged WMI for execution and querying host information. |
| T1057 Process Discovery |
GroupMuddyWater | MuddyWater has used malware to obtain a list of running processes on the system. |
| T1059.001 PowerShell |
GroupMuddyWater | MuddyWater has used PowerShell for execution. ClearSky MuddyWater Nov 2018DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018MuddyWater TrendMicro June 2018NaumaanProofpoint_GlobalClickFix_April2025Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Symantec MuddyWater Dec 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021 |
| T1059.005 Visual Basic |
GroupMuddyWater | MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros. |
| T1082 System Information Discovery |
GroupMuddyWater | MuddyWater has used malware that can collect the victim’s OS version and machine name. |
| T1083 File and Directory Discovery |
GroupMuddyWater | MuddyWater has used malware that checked if the ProgramData folder had folders or files with the keywords "Kasper," "Panda," or "ESET." |
| T1105 Ingress Tool Transfer |
GroupMuddyWater | MuddyWater has used malware that can upload additional files to the victim’s machine. MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data. |
| T1113 Screen Capture |
GroupMuddyWater | MuddyWater has used malware that can capture screenshots of the victim’s machine. |
| T1204.002 Malicious File |
GroupMuddyWater | MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1218.005 Mshta |
GroupMuddyWater | MuddyWater has used mshta.exe to execute its POWERSTATS payload and to pass a PowerShell one-liner for execution. |
| T1218.011 Rundll32 |
GroupMuddyWater | MuddyWater has used malware that leveraged rundll32.exe in a Registry Run key to execute a .dll. |
| T1518.001 Security Software Discovery |
GroupMuddyWater | MuddyWater has used malware to check running processes against a hard-coded list of security tools often used by malware researchers. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMuddyWater | MuddyWater has added Registry Run key |
| T1559.001 Component Object Model |
GroupMuddyWater | MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook. |
| T1559.002 Dynamic Data Exchange |
GroupMuddyWater | MuddyWater has used malware that can execute PowerShell scripts via DDE. |
| T1566.001 Spearphishing Attachment |
GroupMuddyWater | MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022ESET_MuddyWater_Dec2025FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024SOCRadar_MuddyWaterDindoor_Mar2026Securelist MuddyWater Oct 2018Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.