Advanced Spearphishing and PowerShell Backdoors: MuddyWater Targets Belarus, Turkey, and Ukraine
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Dropper,Fileless malware,Malicious Macro,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
The Iranian APT group MuddyWater has launched a new campaign targeting Belarus, Turkey, and Ukraine. Employing spearphishing as their primary infection vector, the attackers use socially engineered malicious documents to initiate a mainly fileless infection chain. These documents ultimately deliver POWERSTATS, a signature PowerShell backdoor capable of file exfiltration, script execution, and other malicious actions. The recent campaign also introduces a second-stage executable not written in PowerShell, which is packed with UPX and employs anti-analysis techniques. The executable gathers system information and communicates with a C&C server.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Financial | Medium |
| Region | Belarus | Verified |
| Region | Turkey | Verified |
| Region | Ukraine | Verified |
Extracted IOCs
- orbe-fzc[.]com
- 08e256cd2fa027552be253ec3bf427b537977f9123adf1f36e7cd2843a057554
- 2f77ec3dd5a5c8146213fdf6ac2df4a25a542cbd809689a5642954f2097e037a
- 925225002364615b964e4e3704876d9b101e4f07169dbb459175248aefb5a0ad
- 93b749082651d7fc0b3caa9df81bad7617b3bd4475de58acfe953dfafc7b3987
- c005e11a037210eb8efe12b8dee794be36151de30b0223f2c9c4b9680cb033c0
- c873532e009f2fc7d3b111636f3bbaa307465e5a99a7f4386bebff2ef8a37a20
- 185[.]117.75.116
Tip: 8 related IOCs (1 IP, 1 domain, 0 URL, 0 email, 6 file hash) to this threat have been found.
Overlaps
Source: Trend Micro - June 2019
Detection (one case): 185[.]117.75.116
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Demystifying the Latest MuddyWater Cyberattacks
Cybersecurity researchers have discovered a new cyberattack campaign targeting organizations in Belarus, Turkey, and Ukraine. Attackers used highly deceptive emails and malicious documents to secretly install software on victims' computers. Once installed, this software gathers system information and establishes a backdoor for further malicious activity.
The attack is attributed to MuddyWater, an Iranian advanced persistent threat (APT) group. They have been active since at least 2017 and are widely known for their effective phishing campaigns and ability to quietly steal data from compromised networks.
The primary goal of this campaign is unauthorized access and data theft. The attackers steal legitimate documents from networks they have already breached, secretly weaponize them, and send them to new victims. This allows them to map out the newly infected computers and prepare to steal additional files.
This specific campaign is focused on organizations within Belarus, Turkey, and Ukraine. Rather than using a massive, scattergun approach, the campaign spreads deliberately by using stolen documents from one compromised organization to infect the next.
While the report does not list every specific industry, the attackers heavily target organizations by spoofing real corporate and government entities. For example, they used a malicious document disguised as a legal update from the Capital Markets Board of Turkey to trick specific regional victims.
Attackers send targeted emails containing fake but highly convincing documents. If a user is tricked into clicking a prompt to "enable content" within the document, hidden software runs in the background. This software gathers computer details, checks its internet connection, and connects to an attacker-controlled server to download further malicious instructions.
Organizations in these regions likely possess sensitive internal data, intellectual property, or strategic communications. By successfully compromising these networks, attackers gain access to valuable intelligence while using the organization's trusted name to launch further attacks.
Organizations should train their staff to easily recognize suspicious emails and strictly avoid enabling macros or content in unsolicited documents. Furthermore, IT teams should monitor computer networks for unauthorized programs running in hidden background folders and block connections to known malicious web addresses.
This is a highly targeted issue. The attackers use customized, socially engineered messages—such as drafting decoy text specifically in the Turkish language—tailored to deceive their intended regional victims rather than attacking the general public.