Iranian intel cyber suite of malware uses open source tools.pdf
ID: 0e3f1f24-b682-4690-886d-f7bfa75f188c
STIX ID: report--0e3f1f24-b682-4690-886d-f7bfa75f188c
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2022-01-13
Last Modified Date: 2022-01-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
U.S. Cyber Command reports that Iranian intelligence actors associated with MuddyWater (an element of MOIS) are using open-source tooling and malware — including PowGoop loaders and Mori Backdoor — to maintain access to victim networks globally; techniques observed include DLL side‑loading, PowerShell script obfuscation, modified base64 C2 communication, and DNS tunneling, and multiple samples and IOCs have been published to VirusTotal.
