news.mlab.sh
Threat intelligence
Threat actor

MuddyWater

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
Iran
Targeted countries
Iran
TLP
WHITE

(Reaqta) MuddyWater is an APT group that has been active throughout 2017, targeting victims in Middle East with in-memory vectors leveraging on Powershell, in a family of attacks now identified as “Living off the land”, as they don’t require the creation of new binaries on the victim’s machine, thus maintaining a low detection profile and a low forensic footprint. The operators behind MuddyWater are likely espionage motivated, we derive this information from the analysis of data and backdoors behaviors. We also find that despite the strong preponderance of victims from Pakistan, the most active targets appear to be in: Saudi Arabia, UAE and Iraq. Amongst the victims we identify a variety of entities with a stronger focus at Governments, Telcos and Oil companies. By tracking the operations we finally figure out that the originating country is likely to be Iran, while it remains harder to ascertain whether MuddyWater is state sponsored or a criminal organization incline to espionage.

Also known as

ATK 51Boggy SerpensCobalt UlsterEarth VetalaG0069ITG17Mango SandstormMercuryMuddyKrillMuddyWaterSeedwormStatic KittenT-APT-14TA450TEMP.ZagrosYellow Nix

Vulnerabilities exploited

Tooling and malware

FooderLP-NotesMoriMuddyViperPOWERSTATSPowGoopRustyWaterSHARPSTATSSmall SieveSTARWHALETsundere BotnetConnectWiseCrackMapExecEmpireKoadicLaZagneMimikatzOut1PowerSploitRcloneRemoteUtilities

MITRE ATT&CK techniques

T1113 Screen CaptureT1090 ProxyT1104 Multi-Stage ChannelsT1105 Ingress Tool TransferT1571 Non-Standard PortT1555 Credentials from Password StoresT1685 Disable or Modify ToolsT1016 System Network Configuration DiscoveryT1033 System Owner/User DiscoveryT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1518 Software DiscoveryT1047 Windows Management InstrumentationT1203 Exploitation for Client ExecutionT1041 Exfiltration Over C2 ChannelT1190 Exploit Public-Facing ApplicationT1566 PhishingT1210 Exploitation of Remote ServicesT1534 Internal SpearphishingT1140 Deobfuscate/Decode Files or Information

Coverage 6