Another Potential MuddyWater Campaign uses Powershell-based PRB-Backdoor - TrendLabs Security Intelligence Blog
ID: c908e570-9f38-46f6-95de-ab815aa0edbd
STIX ID: report--c908e570-9f38-46f6-95de-ab815aa0edbd
Threat Score
72/100
Uploaded: 2026-08-19
Published Date: 2018-06-19
Last Modified Date: 2018-06-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro analyzed a targeted email lure using a macro-enabled Word document that decodes embedded PowerShell code to install a PRB-Backdoor (linked to the MuddyWater actor). The malware communicates with a C2 at out100k.net, supports data theft (browser history/passwords), remote command execution, persistence, and includes distinct dropped components and an SHA256 indicator.
