MuddyWater SmallSieve Campaign

MuddyWater use of SmallSieve backdoor and Telegram-based C2 infrastructure against Iranian dissidents and regional targets.

Start date
1 January 2022
End date
Techniques
14

Attributed actors

Techniques (14)

collection1
T1113Screen Capture
command-and-control3
T1102.002Bidirectional Communication
T1105Ingress Tool Transfer
T1071.001Web Protocols
discovery2
T1082System Information Discovery
T1083File and Directory Discovery
execution3
T1059.003Windows Command Shell
T1059.001PowerShell
T1053.005Scheduled Task
exfiltration1
T1041Exfiltration Over C2 Channel
initial-access1
T1566.001Spearphishing Attachment
persistence2
T1547.001Registry Run Keys / Startup Folder
T1053.005Scheduled Task
privilege-escalation2
T1547.001Registry Run Keys / Startup Folder
T1053.005Scheduled Task
stealth2
T1070.004File Deletion
T1027Obfuscated Files or Information

Indicators of compromise

No IOCs linked to this campaign yet.