Out1

S0594

Tool.View on attack.mitre.org

About this tool

Out1 is a remote access tool written in python and used by MuddyWater since at least 2021.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1005
Data from Local System

Out1 can copy files and Registry data from compromised hosts.

T1027
Obfuscated Files or Information

Out1 has the ability to encode data.

T1059.003
Windows Command Shell

Out1 can use native command line for execution.

T1071.001
Web Protocols

Out1 can use HTTP and HTTPS in communications with remote hosts.

T1114.001
Local Email Collection

Out1 can parse e-mails on a target machine.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Trend Micro Muddy Water March 2021 Open source
    Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.