Fooder

MITRE ATT&CK: S9033 View on attack.mitre.org

Aliases: Fooder

First seen
2021-10-10 00:00:00
Malware type
loader, rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:22:59

Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications

Targeted regions: country_code:ir country_code:sa

Context

Fooder is a custom 64-bit C/C++ loader used by MuddyWater that can decrypt and reflectively load embedded payloads such as a go-socks5 proxy utility, the open-source HackBrowserData infostealer, or the MuddyViper backdoor. Fooder has frequently masqueraded as an entertainment executable, such as the Snake game (e.g., `Snake_Game.exe`).

Detection coverage

  • 138 Sigma rules

Malware & tools used

  • Obfuscated Files or Information (attack-pattern)
  • Token Impersonation/Theft (attack-pattern)
  • Native API (attack-pattern)
  • Reflective Code Loading (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Delay Execution (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)

Used by threat actors

Reports & references

  • ESET — Muddywater Snakes Riverbank (report)
  • MITRE ATT&CK — S9033 (report)

External references