Muddy Water's Evolving Tactics: From BlackWater to H3OpAirStrike
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Malicious Macro,Trojan,Phishing,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
The Muddy Water threat actor, suspected to be a continuation of the previously reported BlackWater campaign, has been observed distributing malicious documents via spearphishing emails. One document focuses on the nomination of Stephen Moore to the Federal Reserve, likely leveraging current events for social engineering. Another targets the oil and gas sector and features a malicious macro named "H3OpAirStrike," potentially referencing historical Iranian air strikes. Both macros communicate with C2 servers and deploy PowerShell trojans. The malware collects various workstation data and uses Invoke-Obfuscation to evade detection.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Oil and Gas | Verified |
| Region | United States | Medium |
Extracted IOCs
- accesemailaccount[.]tk
- account-signin-secure[.]com
- accounts-login[.]ga
- accountslogin[.]ga
- accounts-login[.]gq
- apikeyallervice[.]business
- apikeyallervice[.]com
- loginaccounts[.]cf
- login-accounts[.]gq
- logind2-secure[.]tk
- login-dc2-verifyaccounts[.]ga
- login-dc2-verifyaccounts[.]tk
- login-secure-account[.]cf
- login-secure-account[.]gq
- login-secure-account[.]ml
- roadtosultan1[.]org
- secure-login-accounts[.]gq
- signin-secure[.]tk
- reauth92-services.sytes[.]net
- service0auht-center.ddns[.]net
- 4d72dcd33379fe7a34f9618e692f659fa9d318ab623168cd351c18ca3a805af1
- 95c650a540ed5385bd1caff45ba06ff90dc0773d744efc4c2e4b29dda102fcce
- f327abed77b4b19b4471eaebf722295b8e50a47f36a4d7662cac91b1a622e64a
- f779ccc3da9d8c62a9596c3567b38cabfa1b1292129c1a77db67aaffb7828fe2
- 104[.]237.255.195
- 194[.]187.249.78
- 38[.]132.99.167
- 91[.]132.139.159
- 91[.]132.139.194
- 91[.]132.139.196
- hxxp://104[.]237.255.195/p[.]txt
- hxxp://194[.]187.249.78/
- hxxp://38[.]132.99.167/crf[.]txt
- hxxp://91[.]132.139.196/prxy[.]php?rcecms=h3opairstrike
Tip: 34 related IOCs (6 IP, 20 domain, 4 URL, 0 email, 4 file hash) to this threat have been found.
Overlaps
Source: Trend Micro - June 2019
Detection (four cases): 38[.]132.99.167, hxxp://38[.]132.99.167/crf[.]txt, 4d72dcd33379fe7a34f9618e692f659fa9d318ab623168cd351c18ca3a805af1, 95c650a540ed5385bd1caff45ba06ff90dc0773d744efc4c2e4b29dda102fcce
Source: Rewterz - May 2019
Detection (two cases): 38[.]132.99.167, hxxp://38[.]132.99.167/crf[.]txt
Source: Cisco Talos - May 2019
Detection (two cases): 38[.]132.99.167, hxxp://38[.]132.99.167/crf[.]txt
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Understanding the "Summer Mirage" Cyber Campaign
Security researchers uncovered a cyber espionage campaign dubbed "Summer Mirage". Threat actors used malicious documents and fake login websites to compromise workstations and harvest user credentials.
The campaign is attributed with high confidence to Muddy Water, an Iran-nexus threat group. They have been recognized as an active persistent threat actor since at least November 2017.
The attackers sought to deploy a fully functional remote access trojan on victim computers to gain interactive control over the infected systems. A secondary goal was to harvest end-user credentials via typo-squatted domains that mimicked authentic login services.
The campaign was highly targeted rather than widespread. The threat actors utilized tailored, sector-specific subject matter to infiltrate specialized networks.
Yes, the attackers targeted individuals tracking Stephen Moore's Federal Reserve appointment. They also heavily targeted members of the oil and gas vertical, specifically companies focused on extracting and processing crude oil.
Attackers sent deceptive documents that required victims to enable macros to view the content. Once enabled, these macros downloaded a hidden trojan from an attacker-controlled server to compromise the machine.
While explicit motivations are not detailed, the targeting aligned with the threat group's historical targeting trends and the specific political or industrial subject matter of the documents. Additionally, previously compromised networks in these sectors were noted to be particularly vulnerable to these attacks.
Organizations must thoroughly update their email filters and end-point antivirus solutions. Crucially, employees must be trained to never enable macros on documents sent from unknown or untrusted sources.
This is a carefully targeted campaign aimed at specific verticals and political interests, rather than a widespread attack on the general public.