Malware.View on attack.mitre.org
RustyWater is a Rust-based implant used by MuddyWater. Historically, MuddyWater has used PowerShell-based tools and RustyWater reflects a shift in tooling, demonstrating better techniques for defense evasion and reverse engineering.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
RustyWater has an obfuscated function (i.e. love_me__()) that dynamically reconstructs the string WScript.Shell using hard-coded ASCII values and the Chr() function. |
| T1027.013 Encrypted/Encoded File |
RustyWater has encrypted all strings in the code using position independent XOR encryption. |
| T1033 System Owner/User Discovery |
RustyWater has gathered the victim machine’s username. |
| T1036.005 Match Legitimate Resource Name or Location |
RustyWater has used reddit.exe as its file name and a Cloudflare logo. |
| T1055.002 Portable Executable Injection |
RustyWater has injected its shellcode into explorer.exe by allocating memory via `VirtualAllocEx`, then by writing the payload via `WriteProcessMemory`. |
| T1071.001 Web Protocols |
RustyWater has used the Rust request library for HTTP C2 communication. |
| T1082 System Information Discovery |
RustyWater has gathered the victim machine’s computer name. |
| T1087.002 Domain Account |
RustyWater has gathered the domain membership of the victim machine’s user. |
| T1106 Native API |
RustyWater has used `CreateObject` to instantiate a WScript.Shell Component Object Model (COM) object. Additionally, RustyWater has used `VirtualAllocEx` and `WriteProcessMemory` to inject shellcode into explorer.exe. |
| T1132.001 Standard Encoding |
RustyWater has encoded collected data with Base64. |
| T1140 Deobfuscate/Decode Files or Information |
RustyWater has used the WriteHexToFile function to transform an embedded hex string to the payload CertificationKit.ini. |
| T1204.002 Malicious File |
RustyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. |
| T1518.001 Security Software Discovery |
RustyWater has attempted to detect more than 25 antivirus and EDR tools. |
| T1547.001 Registry Run Keys / Startup Folder |
RustyWater has established persistence by adding `C:\ProgramData\CertificationKit.ini` to a Windows startup Registry key or to a Run or RunOnce Registry key. |
| T1559.001 Component Object Model |
RustyWater has used a WScript.Shell COM object to execute the CertificationKit.ini file. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.