logo

Iranian intel cyber suite of malware uses open source tools.pdf

ID: 0e3f1f24-b682-4690-886d-f7bfa75f188c

STIX ID: report--0e3f1f24-b682-4690-886d-f7bfa75f188c

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2022-01-13

Last Modified Date: 2022-01-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
U.S. Cyber Command reports that Iranian intelligence actors associated with MuddyWater (an element of MOIS) are using open-source tooling and malware — including PowGoop loaders and Mori Backdoor — to maintain access to victim networks globally; techniques observed include DLL side‑loading, PowerShell script obfuscation, modified base64 C2 communication, and DNS tunneling, and multiple samples and IOCs have been published to VirusTotal.