PowGoop

S1046

Malware.View on attack.mitre.org

About this malware

PowGoop is a loader that consists of a DLL loader and a PowerShell-based downloader; it has been used by MuddyWater as their main loader.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1036
Masquerading

PowGoop has disguised a PowerShell script as a .dat file (goopdate.dat).

T1036.005
Match Legitimate Resource Name or Location

PowGoop has used a DLL named Goopdate.dll to impersonate a legitimate Google update file.

T1059.001
PowerShell

PowGoop has the ability to use PowerShell scripts to execute commands.

T1071.001
Web Protocols

PowGoop can send HTTP GET requests to malicious servers.

T1132.002
Non-Standard Encoding

PowGoop can use a modified Base64 encoding mechanism to send data to and from the C2 server.

T1140
Deobfuscate/Decode Files or Information

PowGoop can decrypt PowerShell scripts for execution.

T1573
Encrypted Channel

PowGoop can receive encrypted commands from C2.

T1574.001
DLL

PowGoop can side-load `Goopdate.dll` into `GoogleUpdate.exe`.

Groups that use it1

Campaigns0

None recorded.

References2

  1. CYBERCOM Iranian Intel Cyber January 2022 Open source
    Cyber National Mission Force. (2022, January 12). Iranian intel cyber suite of malware uses open source tools. Retrieved September 30, 2022.
  2. DHS CISA AA22-055A MuddyWater February 2022 Open source
    FBI, CISA, CNMF, NCSC-UK. (2022, February 24). Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks. Retrieved September 27, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.