MuddyWater's Cyber Arsenal: From PowGoop to Mori Backdoor
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,Malware,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
US Cyber Command's Cyber National Mission Force (CNMF) published this advisory on January 12, 2022, disclosing multiple open-source tools used by MuddyWater — a subordinate element of Iran's Ministry of Intelligence and Security (MOIS) — in networks around the world. The advisory identifies several variants of the PowGoop malware suite and the Mori backdoor, and releases file samples to VirusTotal for defender use. PowGoop operates via DLL side-loading: the malicious goopdate.dll is placed alongside the legitimate GoogleUpdate.exe, causing it to load automatically. Once loaded, it deobfuscates a .dat PowerShell script, which in turn decodes a config.txt PowerShell script that establishes C2 communication using a modified Base64 encoding scheme. Additional PowGoop variants use different DLL names (libpcre2-8-0.dll, vcruntime140.dll) to avoid AV and manual detection. JavaScript samples associated with the same actor issue GET requests to malicious infrastructure. The Mori backdoor communicates with C2 infrastructure via DNS tunneling and is identified by two key indicators: creation of the mutex 0x50504060 and the registry key HKLM\SOFTWARE\NFC. CNMF noted that identifying multiple of these tools on the same network strongly indicates the presence of Iranian malicious cyber actors.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Middle East Countries | Medium |
| Region | United States | Medium |
| Region | European Countries | Medium |
FAQs
Frequently Asked Questions About MuddyWater's PowGoop and Mori Backdoor Toolkit
US Cyber Command's Cyber National Mission Force published an advisory on January 12, 2022, disclosing a suite of malware tools used by MuddyWater — an Iranian state-sponsored threat group that operates as a subordinate of Iran's Ministry of Intelligence and Security. The advisory identified multiple variants of the PowGoop malware loader and the Mori backdoor, and released file samples to VirusTotal to help defenders detect and respond to these tools. MuddyWater had been using these tools in networks across the Middle East, Europe, and North America for espionage purposes.
The tools are attributed to MuddyWater, an Iranian threat group assessed by US Cyber Command to be a subordinate element of Iran's Ministry of Intelligence and Security (MOIS). MuddyWater has been active since at least 2017 and is known for targeting government agencies, telecommunications providers, defense contractors, and critical infrastructure organizations across the Middle East, Europe, and North America. The CNMF advisory represents a rare direct US government attribution of specific malware tools to an Iranian intelligence body.
The primary goal was espionage — gaining and maintaining persistent access to victim networks to collect intelligence on behalf of the Iranian government. PowGoop provides a persistent loader that silently runs obfuscated PowerShell C2 scripts, while Mori gives attackers a stealthy DNS-based backdoor for long-term access. The advisory notes that PowGoop has also been associated with ransomware in some cases, suggesting MuddyWater may use the same tooling opportunistically for disruptive operations beyond intelligence collection.
MuddyWater has primarily targeted Middle Eastern nations, with significant focus on government agencies, defense organizations, and telecommunications providers across Turkey, Saudi Arabia, Iraq, Israel, UAE, Jordan, and Egypt. The group has also targeted European and North American organizations. US Cyber Command's advisory reflects the global reach of the campaign — the tools were identified on compromised networks worldwide.
MuddyWater's consistent targeting profile spans government agencies, telecommunications providers, defense contractors, universities, and critical infrastructure organizations. These sectors align directly with Iran's MOIS intelligence collection mandate — monitoring regional rivals, tracking foreign policy decisions, and surveilling activists and dissidents abroad. The advisory notes that MOIS also uses these capabilities domestically to identify regime opponents.
PowGoop uses DLL side-loading — a technique that exploits how Windows loads software libraries. The attackers place a malicious goopdate.dll in the same directory as the legitimate Google Update application (GoogleUpdate.exe). When Google Update runs, Windows automatically loads the malicious DLL instead of the real one. The DLL then reads and deobfuscates a .dat file, which is a PowerShell script that in turn decodes a config.txt file — another PowerShell script that establishes communication with the attacker's C2 server using a modified Base64 encoding scheme. The Mori backdoor takes a different approach: it is loaded via regsvr32.exe and uses DNS tunneling to communicate with C2 infrastructure, creating a mutex (0x50504060) and a registry key (HKLM\SOFTWARE\NFC) during operation.
DLL side-loading is a powerful evasion technique because the malicious DLL runs inside a trusted, legitimate process — in this case Google Update — making it much harder for security tools to flag. The multi-stage PowerShell deobfuscation chain (goopdate.dll → .dat → config.txt) means no single file contains the full malicious payload, reducing the chance of signature detection. Variant DLL names like libpcre2-8-0.dll and vcruntime140.dll further evade antivirus tools looking for known-bad filenames. Mori's DNS tunneling similarly hides C2 traffic inside a protocol that most organizations cannot afford to block, and the traffic blends with normal DNS queries.
Hunt for goopdate.dll placed alongside GoogleUpdate.exe outside its legitimate installation path, and monitor for the variant DLL names libpcre2-8-0.dll and vcruntime140.dll in unusual directories. Alert on Mori-specific IOCs: mutex 0x50504060 at process creation and any write to HKLM\SOFTWARE\NFC. Monitor regsvr32.exe executing DLLs from non-standard paths. Detect multi-stage PowerShell deobfuscation chains — specifically PowerShell reading encoded content from .dat or .txt files. Block and monitor DNS traffic for tunneling patterns (long subdomains, high query rates, TXT record queries from endpoints). Download and deploy the IOC hashes released by US Cyber Command at virustotal.com/en/user/CYBERCOM_Malware_Alert for endpoint detection coverage across all disclosed PowGoop and Mori variants.