logo

Another Potential MuddyWater Campaign uses Powershell-based PRB-Backdoor - TrendLabs Security Intelligence Blog

ID: c908e570-9f38-46f6-95de-ab815aa0edbd

STIX ID: report--c908e570-9f38-46f6-95de-ab815aa0edbd

Threat Score

72/100

Uploaded: 2026-08-19

Published Date: 2018-06-19

Last Modified Date: 2018-06-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro analyzed a targeted email lure using a macro-enabled Word document that decodes embedded PowerShell code to install a PRB-Backdoor (linked to the MuddyWater actor). The malware communicates with a C2 at out100k.net, supports data theft (browser history/passwords), remote command execution, persistence, and includes distinct dropped components and an SHA256 indicator.