Excel-Based Macro Attacks: MuddyWater's Evolving Cyber Strategy
- Actor Motivations: Espionage
- Attack Vectors: Dropper,Malicious Macro,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: Low Impact/Low Probability
Threat Overview
The MuddyWater group conducted a cyberattack campaign during October-November 2019, employing spear phishing emails with macro-infected Excel documents. These emails delivered a file named “Report.xls,” which, when opened and macros were enabled, executed malicious activities including dropping files and creating network connections to a harmful domain. This campaign involved using legitimate Microsoft files for script execution and establishing command and control channels. NetWitness tools were utilized to highlight risky behaviors, registry changes for persistence, and unusual network communications.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Middle East Countries | High |
Extracted IOCs
- ampacindustries[.]com
- annapolisfirstlimo[.]com
- assignmenthelptoday[.]com
- graphixo[.]net
- ksahosting[.]net
- 1cd71f39ff9fb3bf269440b63c717195
- 269afae11cc9837e732019a03fa02fab
- 2c3a634953a9a2c227a51e8eeac9f137
- 32156247f900883d5106795ec103a624
- 4022bbb9df5d86226bd9a89f361c94b9
- 46f911014f1202e17936f627f34e6165
- 50ac74eb38d6fa07d9f5e788d61a92cd
- 584479a1958a73720c4aebb52c59b21e
- 5ef459908d5be0672b02cdfe4f606989
- 66c783e41480e65e287081ff853cc737
- 7ed6c5e8c3ec4f9499eb793d69a06758
- 9d0bfb81f450de8364327a4aaa67d9b3
- a9706c01de9364eab210ea73296bfe71
- b100c0cfbe59fa66cbb75de65c505ce2
- b9ee416f2d9557be692abf448bf2f937
- e18228bee6f1cf12eaf1bb4d5be587bf
- 905e3f74e5dcca58cf6bb3afaec888a3d6cb7529b6e4974e417b2c8392929148
- hxxp://ampacindustries[.]com/css/utf8.php
- hxxp://graphixo[.]net/wp-includes/utf8.php
- hxxp://ksahosting[.]net/wp-includes/utf8.php
- hxxps://annapolisfirstlimo[.]com/editob.nvd
- hxxps://assignmenthelptoday[.]com/wp-includes/utf8.php
Tip: 27 related IOCs (0 IP, 5 domain, 5 URL, 0 email, 17 file hash) to this threat have been found.
Overlaps
Source: Secureworks - February 2020
Detection (six cases): hxxp://ksahosting[.]net/wp-includes/utf8.php, hxxps://assignmenthelptoday[.]com/wp-includes/utf8.php, ampacindustries[.]com, assignmenthelptoday[.]com, graphixo[.]net, ksahosting[.]net
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
MuddyWater Cyber Attack Campaign
A state-sponsored cyber attack campaign was detected using malicious Excel documents to compromise organization systems. Once opened by a user, the infected spreadsheet drops hidden script files and establishes background connections to an external server.
The activity has been attributed to MuddyWater, a state-sponsored threat actor group suspected of having links to Iran. The group is known for conducting targeted cyber reconnaissance and espionage operations.
The campaign specifically targeted key regional infrastructure, focusing on organizations in the Telecommunications, Government, and Oil sectors across the Middle East. The primary goal involved establishing persistence on compromised endpoints and exfiltrating system and user identification details.
The attackers distributed spear-phishing emails carrying macro-enabled Excel attachments. When open, the file prompts the recipient to enable content, triggering macros that save and launch malicious script files, set up automatic startup entries, and communicate with an external domain over standard web traffic.
This is a highly targeted campaign directed at specific critical sectors within the Middle East rather than a broad, opportunistic attack against the general public.
Organizations should restrict macro execution in office applications, monitor endpoints for unusual startup registry entries or file creations in temporary folders, and leverage network security feeds to block known malicious domains.