ATT&CKSoftwareStrifeWater

StrifeWater

S1034

Malware.View on attack.mitre.org

About this malware

StrifeWater is a remote-access tool that has been used by Moses Staff in the initial stages of their attacks since at least November 2021.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

StrifeWater can collect data from a compromised host.

T1033
System Owner/User Discovery

StrifeWater can collect the user name from the victim's machine.

T1036.005
Match Legitimate Resource Name or Location

StrifeWater has been named `calc.exe` to appear as a legitimate calculator program.

T1041
Exfiltration Over C2 Channel

StrifeWater can send data and files from a compromised host to its C2 server.

T1053.005
Scheduled Task

StrifeWater has create a scheduled task named `Mozilla\Firefox Default Browser Agent 409046Z0FF4A39CB` for persistence.

T1059.003
Windows Command Shell

StrifeWater can execute shell commands using `cmd.exe`.

T1070.004
File Deletion

StrifeWater can self delete to cover its tracks.

T1082
System Information Discovery

StrifeWater can collect the OS version, architecture, and machine name to create a unique token for the infected host.

T1083
File and Directory Discovery

StrifeWater can enumerate files on a compromised host.

T1105
Ingress Tool Transfer

StrifeWater can download updates and auxiliary modules.

T1106
Native API

StrifeWater can use a variety of APIs for execution.

T1113
Screen Capture

StrifeWater has the ability to take screen captures.

T1124
System Time Discovery

StrifeWater can collect the time zone from the victim's machine.

T1497.003
Time Based Checks

StrifeWater can modify its sleep time responses from the default of 20-22 seconds.

T1573.001
Symmetric Cryptography

StrifeWater can encrypt C2 traffic using XOR with a hard coded key.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cybereason StrifeWater Feb 2022 Open source
    Cybereason Nocturnus. (2022, February 1). StrifeWater RAT: Iranian APT Moses Staff Adds New Trojan to Ransomware Operations. Retrieved August 15, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.