Malware.View on attack.mitre.org
MuddyViper is custom backdoor written in C and C++ used by MuddyWater for command and control (C2) communications and persistence. MuddyViper is loaded by Fooder and sends frequent messages to the C2 server.
| Technique | Procedure example |
|---|---|
| T1041 Exfiltration Over C2 Channel |
MuddyViper has uploaded files to the C2 server. Additionally, MuddyViper has the ability to upload the specified file in chunks with sleep time between each chunk. |
| T1053.005 Scheduled Task |
MuddyViper has the ability to establish persistence by creating a scheduled task named ManageOnDriveUpdater to launch itself during system startup. |
| T1056.002 GUI Input Capture |
MuddyViper has displayed a fake Windows Security dialog to gather credentials. |
| T1057 Process Discovery |
MuddyViper has the ability to collect running processes. |
| T1059 Command and Scripting Interpreter |
MuddyViper has launched a reverse shell using a provided command line. |
| T1059.001 PowerShell |
MuddyViper has used PowerShell.exe to launch a reverse shell. |
| T1059.003 Windows Command Shell |
MuddyViper has used cmd.exe to launch a reverse shell. |
| T1071.001 Web Protocols |
MuddyViper has used HTTP GET requests over port 443 and with the WINHTTP_FLAG_SECURE set to SSL/TLS via the WinHTTP API. |
| T1105 Ingress Tool Transfer |
MuddyViper has the ability to download files from the C2 server. Additionally, MuddyViper has the ability to download a file in chunks with sleep time between each chunk. |
| T1106 Native API |
MuddyViper has the ability to relaunch itself using the `CreateProcessW` API. |
| T1112 Modify Registry |
MuddyViper has the ability to clear the Registry values in the Windows Startup folder that were previously set for persistence. |
| T1140 Deobfuscate/Decode Files or Information |
MuddyViper has decrypted the embedded HackBrowserData tool prior to execution. |
| T1518.001 Security Software Discovery |
MuddyViper has the ability to check for a specified list of security tools in the compromised environment. |
| T1547.001 Registry Run Keys / Startup Folder |
MuddyViper has the ability to establish persistence by configuring its installation directory as a Windows Startup folder by setting the following Registry values to `%APPDATALOCAL%\Microsoft\Windows\PPBCompatCache\ManagerCache`: `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup`. |
| T1560 Archive Collected Data |
MuddyViper has archived collected web browser data into a file named CacheDump.zip. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.