Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupMuddyWater | MuddyWater has performed credential dumping with Mimikatz and procdump64.exe. |
| T1005 Data from Local System |
ToolOut1 | Out1 can copy files and Registry data from compromised hosts. |
| T1027 Obfuscated Files or Information |
ToolOut1 | Out1 has the ability to encode data. |
| T1027.010 Command Obfuscation |
GroupMuddyWater | MuddyWater has used Daniel Bohannon’s Invoke-Obfuscation framework and obfuscated PowerShell scripts. The group has also used other obfuscation methods, including Base64 obfuscation of VBScripts and PowerShell commands. |
| T1033 System Owner/User Discovery |
GroupMuddyWater | MuddyWater has used malware that can collect the victim’s username. |
| T1049 System Network Connections Discovery |
GroupMuddyWater | MuddyWater has used a PowerShell backdoor to check for Skype connections on the target machine. |
| T1059.001 PowerShell |
GroupMuddyWater | MuddyWater has used PowerShell for execution. ClearSky MuddyWater Nov 2018DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018MuddyWater TrendMicro June 2018NaumaanProofpoint_GlobalClickFix_April2025Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Symantec MuddyWater Dec 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021 |
| T1059.003 Windows Command Shell |
ToolOut1 | Out1 can use native command line for execution. |
| T1059.005 Visual Basic |
GroupMuddyWater | MuddyWater has used VBScript files to execute its POWERSTATS payload, as well as macros. |
| T1059.006 Python |
GroupMuddyWater | MuddyWater has developed tools in Python including Out1. |
| T1071.001 Web Protocols |
ToolOut1 | Out1 can use HTTP and HTTPS in communications with remote hosts. |
| T1071.001 Web Protocols |
GroupMuddyWater | MuddyWater has used HTTP for C2 communications. |
| T1082 System Information Discovery |
GroupMuddyWater | MuddyWater has used malware that can collect the victim’s OS version and machine name. |
| T1083 File and Directory Discovery |
ToolRemoteUtilities | RemoteUtilities can enumerate files and directories on a target machine. |
| T1087.002 Domain Account |
GroupMuddyWater | MuddyWater has used |
| T1090.002 External Proxy |
GroupMuddyWater | MuddyWater has controlled POWERSTATS from behind a proxy network to obfuscate the C2 location. MuddyWater has used a series of compromised websites that victims connected to randomly to relay information to command and control (C2). MuddyWater has also used go-socks5 variants to bypass firewalls and Network Address Translation (NAT), to communicate with a hardcoded C2 server, and to exfiltrate data. |
| T1105 Ingress Tool Transfer |
GroupMuddyWater | MuddyWater has used malware that can upload additional files to the victim’s machine. MuddyWater has used PowerShell commands to install remote management and monitoring (RMM) software on the victim’s machine to conduct espionage and to exfiltrate data. |
| T1105 Ingress Tool Transfer |
ToolRemoteUtilities | RemoteUtilities can upload and download files to and from a target machine. |
| T1113 Screen Capture |
ToolRemoteUtilities | RemoteUtilities can take screenshots on a compromised host. |
| T1114.001 Local Email Collection |
ToolOut1 | Out1 can parse e-mails on a target machine. |
| T1132.001 Standard Encoding |
GroupMuddyWater | MuddyWater has used tools to encode C2 communications including Base64 encoding. |
| T1204.001 Malicious Link |
GroupMuddyWater | MuddyWater has distributed URLs in phishing e-mails that link to lure documents. |
| T1204.002 Malicious File |
GroupMuddyWater | MuddyWater has attempted to get users to open malicious PDF attachment and to enable macros and launch malicious Microsoft Word documents delivered via spearphishing emails. Additionally, MuddyWater has used a Word document with a malicious Visual Basic for Applications (VBA) macro; when enabled, the CertificationKit.ini payload is constructed and executed. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024Reaqta MuddyWater November 2017Securelist MuddyWater Oct 2018Talos MuddyWater Jan 2022Talos MuddyWater May 2019Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1218.007 Msiexec |
ToolRemoteUtilities | RemoteUtilities can use Msiexec to install a service. |
| T1219.002 Remote Desktop Software |
GroupMuddyWater | MuddyWater has leveraged RMM solutions including ScreenConnect, AteraAgent, SimpleHelp, Action1, Level, and PDQ to facilitate follow-on actions within compromised hosts to include data exfiltration. |
| T1518 Software Discovery |
GroupMuddyWater | MuddyWater has used a PowerShell backdoor to check for Skype connectivity on the target machine. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMuddyWater | MuddyWater has added Registry Run key |
| T1555 Credentials from Password Stores |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne and other tools, including by dumping passwords saved in victim email. |
| T1555.003 Credentials from Web Browsers |
GroupMuddyWater | MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers. |
| T1566.001 Spearphishing Attachment |
GroupMuddyWater | MuddyWater has compromised third parties and used compromised accounts to send spearphishing emails with targeted attachments to recipients. MuddyWater has also sent spearphishing emails with the attachment Cybersecurity.doc, which served as the primarily payload for the next stage. Anomali Static Kitten February 2021ClearSky MuddyWater June 2019CloudSEK_RustyWater_Jan2026DHS CISA AA22-055A MuddyWater February 2022ESET_MuddyWater_Dec2025FireEye MuddyWater Mar 2018Proofpoint TA450 Phishing March 2024SOCRadar_MuddyWaterDindoor_Mar2026Securelist MuddyWater Oct 2018Trend Micro Muddy Water March 2021Unit 42 MuddyWater Nov 2017 |
| T1566.002 Spearphishing Link |
GroupMuddyWater | MuddyWater has sent targeted spearphishing e-mails with malicious links. |
| T1583.006 Web Services |
GroupMuddyWater | MuddyWater has used file sharing services including OneHub, Sync, and TeraBox to distribute tools. |
| T1685 Disable or Modify Tools |
GroupMuddyWater | MuddyWater can disable the system's local proxy settings. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.