Fooder
MITRE ATT&CK: S9033 View on attack.mitre.org
Aliases: Fooder
- First seen
- 2021-10-10 00:00:00
- Malware type
- loader, rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:22:59
Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications
Targeted regions: country_code:ir country_code:sa
Context
Fooder is a custom 64-bit C/C++ loader used by MuddyWater that can decrypt and reflectively load embedded payloads such as a go-socks5 proxy utility, the open-source HackBrowserData infostealer, or the MuddyViper backdoor. Fooder has frequently masqueraded as an entertainment executable, such as the Snake game (e.g., `Snake_Game.exe`).
Detection coverage
- 138 Sigma rules
Malware & tools used
- Obfuscated Files or Information (attack-pattern)
- Token Impersonation/Theft (attack-pattern)
- Native API (attack-pattern)
- Reflective Code Loading (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Delay Execution (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Used by threat actors
- MuddyWater (threat-actor)
Reports & references
- ESET — Muddywater Snakes Riverbank (report)
- MITRE ATT&CK — S9033 (report)