MuddyWater's BlackWater: An In-depth Look at Advanced TTPs
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Malicious Macro,Trojan,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
The MuddyWater-associated BlackWater campaign has displayed advanced TTPs in its latest activities. Using obfuscated VBA and PowerShell scripts, the threat actors establish persistence via registry keys and utilize multi-staging payloads. The campaign employs an open-source framework, FruityC2, to further enumerate the victim's host machine and evade signature-based detection mechanisms. The actor-controlled servers are used for command and control, making host-based detection challenging. Compared to earlier samples, the new tactics require a multi-step investigative approach.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Middle East Countries | Medium |
Extracted IOCs
- 062a8728e7fcf2ff453efc56da60631c738d9cd6853d8701818f18a4e77f8717
- 0d3e0c26f7f53dff444a37758b414720286f92da55e33ca0e69edc3c7f040ce2
- 0f3cabc7f1e69d4a09856cc0135f7945850c1eb6aeecd010f788b3b8b4d91cad
- 4dd641df0f47cb7655032113343d53c0e7180d42e3549d08eb7cb83296b22f60
- 576d1d98d8669df624219d28abcbb2be0080272fa57bf7a637e2a9a669e37acf
- 6f882cc0cddd03bc123c8544c4b1c8b9267f4143936964a128aa63762e582aad
- 9d998502c3999c4715c880882efa409c39dd6f7e4d8725c2763a30fbb55414b7
- a3bb6b3872dd7f0812231a480881d4d818d2dea7d2c8baed858b20cb318da981
- b2600ac9b83e5bb5f3d128dbb337ab1efcdc6ce404adb6678b062e95dbf10c93
- bef9051bb6e85d94c4cfc4e03359b31584be027e87758483e3b1e65d389483e6
- 136[.]243.87.112
- 38[.]132.99.167
- 82[.]102.8.101
- 94[.]23.148.194
- hxxp://136[.]243.87.112:3000/kls6yug5df
- hxxp://136[.]243.87.112:3000/ll5jh6f4bh
- hxxp://136[.]243.87.112:3000/y3zp6ns7kg
- hxxp://38[.]132.99.167/crf[.]txt
- hxxp://82[.]102.8.101:80/bcerrxy[.]php?rcecms=blackwater
- hxxp://82[.]102.8.101/bcerrxy[.]php
- hxxp://94[.]23.148.194/serverscript/clientfrontline/
- hxxp://94[.]23.148.194/serverscript/clientfrontline/getcommand[.]php
- hxxp://94[.]23.148.194/serverscript/clientfrontline/helloserver[.]php
Tip: 23 related IOCs (4 IP, 0 domain, 9 URL, 0 email, 10 file hash) to this threat have been found.
Overlaps
Source: Picussecurity - March 2022
Detection (three cases): 0d3e0c26f7f53dff444a37758b414720286f92da55e33ca0e69edc3c7f040ce2, a3bb6b3872dd7f0812231a480881d4d818d2dea7d2c8baed858b20cb318da981, bef9051bb6e85d94c4cfc4e03359b31584be027e87758483e3b1e65d389483e6
Source: Prevailion - January 2020
Detection (two cases): 38[.]132.99.167, hxxp://38[.]132.99.167/crf[.]txt
Source: Trend Micro - June 2019
Detection (four cases): 38[.]132.99.167, 82[.]102.8.101, hxxp://38[.]132.99.167/crf[.]txt, hxxp://82[.]102.8.101/bcerrxy[.]php
Source: Rewterz - May 2019
Detection (13 cases): 136[.]243.87.112, 38[.]132.99.167, 82[.]102.8.101, 94[.]23.148.194, hxxp://136[.]243.87.112:3000/kls6yug5df, hxxp://136[.]243.87.112:3000/ll5jh6f4bh, hxxp://136[.]243.87.112:3000/y3zp6ns7kg, hxxp://38[.]132.99.167/crf[.]txt, hxxp://82[.]102.8.101/bcerrxy[.]php, hxxp://82[.]102.8.101:80/bcerrxy[.]php?rcecms=blackwater, hxxp://94[.]23.148.194/serverscript/clientfrontline/, hxxp://94[.]23.148.194/serverscript/clientfrontline/getcommand[.]php, hxxp://94[.]23.148.194/serverscript/clientfrontline/helloserver[.]php
Source: ClearSky - April 2019
Detection (six cases): 94[.]23.148.194, 062a8728e7fcf2ff453efc56da60631c738d9cd6853d8701818f18a4e77f8717, 0d3e0c26f7f53dff444a37758b414720286f92da55e33ca0e69edc3c7f040ce2, 4dd641df0f47cb7655032113343d53c0e7180d42e3549d08eb7cb83296b22f60, 6f882cc0cddd03bc123c8544c4b1c8b9267f4143936964a128aa63762e582aad, bef9051bb6e85d94c4cfc4e03359b31584be027e87758483e3b1e65d389483e6
Source: 360 Threat Intelligence Center - March 2019
Detection (one case): 94[.]23.148.194
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
The MuddyWater "BlackWater" Campaign
Security researchers discovered a new cyberattack campaign in April 2019 dubbed "BlackWater." The attackers used malicious documents to secretly install a backdoor on victims' computers. They employed new, multi-step techniques specifically designed to bypass security controls and hide their activities.
Researchers believe with moderate confidence that a persistent threat group known as MuddyWater is behind this campaign. MuddyWater has been actively conducting cyber operations since at least November 2017 and is known for continuing its attacks even after being publicly exposed by security researchers.
The primary goal of the attack was to establish remote access to the victim's machine by installing a hidden backdoor. Once inside, the attackers focused on silently gathering identifying information about the computer and the network it belonged to, while carefully monitoring to see if security teams were investigating them.
While the exact number of victims is not specified, this campaign is part of a larger, ongoing series of operations. The threat actors continuously evolve their methods, indicating a sustained and committed effort to infiltrate their targets.
The group has a well-known history of primarily targeting organizations located in the Middle East, including entities based in Turkey. The attackers used a fake document titled "company information list.doc" to trick victims, suggesting they were aiming at corporate or professional personnel.
The attack likely began with a deceptive phishing email containing a malicious document. When a user opened the document and enabled its features, a hidden script ran in the background to ensure the malware would survive computer restarts. Finally, it used built-in computer management tools to gather system details and quietly transmitted them back to the attackers over the internet.
The focus on Middle Eastern and Turkish entities aligns with MuddyWater's historical regional interests. Gaining remote access to corporate networks in these areas allows the attackers to maintain a hidden foothold for long-term intelligence gathering or future operations.
Organizations should be extremely cautious with email attachments, especially documents that ask users to enable macros or special features. Security teams should proactively hunt for the new hiding techniques used in this campaign, as standard automated security rules may not catch the attackers' disguised network traffic.
This appears to be a targeted issue driven by a specific, persistent threat group. The attackers are deliberately focusing on certain regional organizations and customizing their tools to evade detection at those specific locations.