Mori

S1047

Malware.View on attack.mitre.org

About this malware

Mori is a backdoor that has been used by MuddyWater since at least January 2022.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1001.001
Junk Data

Mori has obfuscated the FML.dll with 200MB of junk data.

T1012
Query Registry

Mori can read data from the Registry including from `HKLM\Software\NFC\IPA` and
`HKLM\Software\NFC\`.

T1070.004
File Deletion

Mori can delete its DLL file and related files by Registry value.

T1071.001
Web Protocols

Mori can communicate using HTTP over IPv4 or IPv6 depending on a flag set.

T1071.004
DNS

Mori can use DNS tunneling to communicate with C2.

T1112
Modify Registry

Mori can write data to `HKLM\Software\NFC\IPA` and `HKLM\Software\NFC\` and delete Registry values.

T1132.001
Standard Encoding

Mori can use Base64 encoded JSON libraries used in C2.

T1140
Deobfuscate/Decode Files or Information

Mori can resolve networking APIs from strings that are ADD-encrypted.

T1218.010
Regsvr32

Mori can use `regsvr32.exe` for DLL execution.

Groups that use it1

Campaigns0

None recorded.

References2

  1. CYBERCOM Iranian Intel Cyber January 2022 Open source
    Cyber National Mission Force. (2022, January 12). Iranian intel cyber suite of malware uses open source tools. Retrieved September 30, 2022.
  2. DHS CISA AA22-055A MuddyWater February 2022 Open source
    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.