ATT&CKReferencesSecurelist MuddyWater Oct 2018

Securelist MuddyWater Oct 2018

Kaspersky Lab's Global Research & Analysis Team. (2018, October 10). MuddyWater expands operations. Retrieved November 2, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupMuddyWater

MuddyWater has used malware to collect the victim’s IP address and domain name.

T1027.010
Command Obfuscation
GroupMuddyWater

MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands.

T1033
System Owner/User Discovery
GroupMuddyWater

MuddyWater has used malware that can collect the victim’s username.

T1047
Windows Management Instrumentation
GroupMuddyWater

MuddyWater has used malware that leveraged WMI for execution and querying host information.

T1057
Process Discovery
GroupMuddyWater

MuddyWater has used malware to obtain a list of running processes on the system.

T1059.001
PowerShell
GroupMuddyWater

MuddyWater has used PowerShell for execution.

T1059.005
Visual Basic
GroupMuddyWater

MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros.

T1082
System Information Discovery
GroupMuddyWater

MuddyWater has used malware that can collect the victim’s OS version and machine name.

T1083
File and Directory Discovery
GroupMuddyWater

MuddyWater has used malware that checked if the ProgramData folder had folders or files with the keywords "Kasper," "Panda," or "ESET."

T1105
Ingress Tool Transfer
GroupMuddyWater

MuddyWater has used malware that can upload additional files to the victim’s machine. MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data.

T1113
Screen Capture
GroupMuddyWater

MuddyWater has used malware that can capture screenshots of the victim’s machine.

T1204.002
Malicious File
GroupMuddyWater

MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed.

T1218.005
Mshta
GroupMuddyWater

MuddyWater has used mshta.exe to execute its POWERSTATS payload and to pass a PowerShell one-liner for execution.

T1218.011
Rundll32
GroupMuddyWater

MuddyWater has used malware that leveraged rundll32.exe in a Registry Run key to execute a .dll.

T1518.001
Security Software Discovery
GroupMuddyWater

MuddyWater has used malware to check running processes against a hard-coded list of security tools often used by malware researchers.

T1547.001
Registry Run Keys / Startup Folder
GroupMuddyWater

MuddyWater has added Registry Run key KCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemTextEncoding to establish persistence.

T1559.001
Component Object Model
GroupMuddyWater

MuddyWater has used malware that has the capability to execute malicious code via COM, DCOM, and Outlook.

T1559.002
Dynamic Data Exchange
GroupMuddyWater

MuddyWater has used malware that can execute PowerShell scripts via DDE.

T1566.001
Spearphishing Attachment
GroupMuddyWater

MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.