PowGoop

MITRE ATT&CK: S1046 View on attack.mitre.org

Aliases: PowGoop

First seen
2020-09-01 00:00:00
Malware type
loader
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:38:54

Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities

Targeted regions: country_code:ir

Context

PowGoop is a loader that consists of a DLL loader and a PowerShell-based downloader; it has been used by MuddyWater as their main loader.

Detection coverage

  • 3 YARA rules
  • 360 Sigma rules

Malware & tools used

  • Encrypted Channel (attack-pattern)
  • Masquerading (attack-pattern)
  • Web Protocols (attack-pattern)
  • PowerShell (attack-pattern)
  • DLL (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Non-Standard Encoding (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Apt_Muddywater_Powgoop_Decode_Loop (yara-rule)
  • SEKOIA_Apt_Muddywater_Powgoop_Loader (yara-rule)
  • SEKOIA_Apt_Muddywater_Powgoop_Decoded (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • CISA — Aa22 055A (report)
  • cybercom.mil — Iranian Intel Cyber Suite Of Malware Uses Open Source Tools (report)
  • CISA — Aa22 055A Iranian Government Sponsored Actors Conduct Cyber Operations (report)
  • inforisktoday.com — Muddywater Targets Critical Infrastructure In Asia Europe A 18611 (report)
  • thehackernews.com — Irans Muddywater Hacker Group Using New (report)
  • malpedia.caad.fkie.fraunhofer.de — Ps1.Powgoop (report)
  • cyberscoop.com — Muddywater Iran Symantec Middle East (report)
  • security.ntt — Analysis Of An Iranian Apts E400 Powgoop Variant (report)
  • Broadcom/Symantec — Seedworm Apt Iran Middle East (report)
  • sentinelone.com — Wading Through Muddy Waters Recent Activity Of An Iranian State Sponsored Threat Actor (report)
  • Palo Alto Unit 42 — Thanos Ransomware (report)
  • clearskysec.com — Operation Quicksand (report)
  • MITRE ATT&CK — S1046 (report)

External references