Malware.View on attack.mitre.org
Fooder is a custom 64-bit C/C++ loader used by MuddyWater that can decrypt and reflectively load embedded payloads such as a go-socks5 proxy utility, the open-source HackBrowserData infostealer, or the MuddyViper backdoor. Fooder has frequently masqueraded as an entertainment executable, such as the Snake game (e.g., `Snake_Game.exe`).
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
Fooder has stored its embedded payload in encrypted form within the binary, using a hardcoded key modified at runtime to produce the AES decryption key. |
| T1036.005 Match Legitimate Resource Name or Location |
Fooder has frequently masqueraded as the Snake game, using strings such as “Welcome to snake Game” and mutexes such as “SNAKE_G.” |
| T1106 Native API |
Fooder has used the WinCrypt API for payload decryption, `DuplicateTokenEx` to duplicate the token of a specified process, and `CreateProcessAsUserA` for payload execution. |
| T1134.001 Token Impersonation/Theft |
Fooder has used the `DuplicateTokenEx` API to duplicate the token of a specified process, and `CreateProcessAsUserA` to execute its payload. |
| T1140 Deobfuscate/Decode Files or Information |
Fooder has decrypted payloads using the WinCrypt API and the AES key. |
| T1620 Reflective Code Loading |
Fooder has reflectively loaded a payload into memory. |
| T1678 Delay Execution |
Fooder has used a custom delay function (`delayExecution(integer)`) and Sleep API calls (`Sleep(integer)`) to slow code execution. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.