MuddyWater Resurfaces, Uses Multi-Stage Backdoor POWERSTATS V3 and New Post-Exploitation Tools - TrendLabs Security Intelligence Blog
ID: 3a8f40da-2fc8-405b-a350-b29a0f81f12b
STIX ID: report--3a8f40da-2fc8-405b-a350-b29a0f81f12b
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2019-06-11
Last Modified Date: 2019-06-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro analyzed MuddyWater activity in H1 2019 and found renewed campaigns using spear-phishing with malicious documents to deliver a multi-stage PowerShell backdoor (POWERSTATS v3) and secondary payloads; the report describes obfuscation techniques, C2 behavior, GUID-based victim identification, use of CVE-2017-11882 template injection, and a range of open-source post-exploitation tools (e.g., Mimikatz, Empire, LaZagne) used by the actors.
