ATT&CKSoftwareMuddyViper

MuddyViper

S9032

Malware.View on attack.mitre.org

About this malware

MuddyViper is custom backdoor written in C and C++ used by MuddyWater for command and control (C2) communications and persistence. MuddyViper is loaded by Fooder and sends frequent messages to the C2 server.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1041
Exfiltration Over C2 Channel

MuddyViper has uploaded files to the C2 server. Additionally, MuddyViper has the ability to upload the specified file in chunks with sleep time between each chunk.

T1053.005
Scheduled Task

MuddyViper has the ability to establish persistence by creating a scheduled task named ManageOnDriveUpdater to launch itself during system startup.

T1056.002
GUI Input Capture

MuddyViper has displayed a fake Windows Security dialog to gather credentials.

T1057
Process Discovery

MuddyViper has the ability to collect running processes.

T1059
Command and Scripting Interpreter

MuddyViper has launched a reverse shell using a provided command line.

T1059.001
PowerShell

MuddyViper has used PowerShell.exe to launch a reverse shell.

T1059.003
Windows Command Shell

MuddyViper has used cmd.exe to launch a reverse shell.

T1071.001
Web Protocols

MuddyViper has used HTTP GET requests over port 443 and with the WINHTTP_FLAG_SECURE set to SSL/TLS via the WinHTTP API.

T1105
Ingress Tool Transfer

MuddyViper has the ability to download files from the C2 server. Additionally, MuddyViper has the ability to download a file in chunks with sleep time between each chunk.

T1106
Native API

MuddyViper has the ability to relaunch itself using the `CreateProcessW` API.

T1112
Modify Registry

MuddyViper has the ability to clear the Registry values in the Windows Startup folder that were previously set for persistence.

T1140
Deobfuscate/Decode Files or Information

MuddyViper has decrypted the embedded HackBrowserData tool prior to execution.

T1518.001
Security Software Discovery

MuddyViper has the ability to check for a specified list of security tools in the compromised environment.

T1547.001
Registry Run Keys / Startup Folder

MuddyViper has the ability to establish persistence by configuring its installation directory as a Windows Startup folder by setting the following Registry values to `%APPDATALOCAL%\Microsoft\Windows\PPBCompatCache\ManagerCache`:  `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup` and `HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Startup`.

T1560
Archive Collected Data

MuddyViper has archived collected web browser data into a file named CacheDump.zip.

View all 18 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET_MuddyWater_Dec2025 Open source
    ESET Research. (2025, December 2). MuddyWater: Snakes by the riverbank. Retrieved February 17, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.