STARWHALE

S1037

Malware.View on attack.mitre.org

About this malware

STARWHALE is Windows Script File (WSF) backdoor that has been used by MuddyWater, possibly since at least November 2021; there is also a STARWHALE variant written in Golang with similar capabilities. Security researchers have also noted the use of STARWHALE by UNC3313, which may be associated with MuddyWater.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1005
Data from Local System

STARWHALE can collect data from an infected local host.

T1016
System Network Configuration Discovery

STARWHALE has the ability to collect the IP address of an infected host.

T1027.013
Encrypted/Encoded File

STARWHALE has been obfuscated with hex-encoded strings.

T1033
System Owner/User Discovery

STARWHALE can gather the username from an infected host.

T1041
Exfiltration Over C2 Channel

STARWHALE can exfiltrate collected data to its C2 servers.

T1059.003
Windows Command Shell

STARWHALE has the ability to execute commands via `cmd.exe`.

T1059.005
Visual Basic

STARWHALE can use the VBScript function `GetRef` as part of its persistence mechanism.

T1071.001
Web Protocols

STARWHALE has the ability to contact actor-controlled C2 servers via HTTP.

T1074.001
Local Data Staging

STARWHALE has stored collected data in a file called `stari.txt`.

T1082
System Information Discovery

STARWHALE can gather the computer name of an infected host.

T1132.001
Standard Encoding

STARWHALE has the ability to hex-encode collected data from an infected host.

T1204.002
Malicious File

STARWHALE has relied on victims opening a malicious Excel file for execution.

T1543.003
Windows Service

STARWHALE has the ability to create the following Windows service to establish persistence on an infected host: `sc create Windowscarpstss binpath= "cmd.exe /c cscript.exe c:\\windows\\system32\\w7_1.wsf humpback_whale" start= "auto" obj= "LocalSystem"`.

T1547.001
Registry Run Keys / Startup Folder

STARWHALE can establish persistence by installing itself in the startup folder, whereas the GO variant has created a `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OutlookM` registry key.

Groups that use it1

Campaigns0

None recorded.

References2

  1. DHS CISA AA22-055A MuddyWater February 2022 Open source
    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.
  2. Mandiant UNC3313 Feb 2022 Open source
    Tomcik, R. et al. (2022, February 24). Left On Read: Telegram Malware Spotted in Latest Iranian Cyber Espionage Activity. Retrieved August 18, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.