New PowerShell-based Backdoor Found in Turkey, Strikingly Similar to MuddyWater Tools
ID: cae4bfbf-232c-4957-9325-921373a69df6
STIX ID: report--cae4bfbf-232c-4957-9325-921373a69df6
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2018-12-06
Last Modified Date: 2018-12-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro discovered a PowerShell-based backdoor, similar to MuddyWater's POWERSTATS, used in spear-phishing campaigns targeting Turkish government finance and energy organizations; malicious Office documents drop an obfuscated PowerShell DLL, establish persistence via the Run registry, and use a cloud file hosting service as an asynchronous C2/exfiltration channel. The report includes technical analysis of the backdoor, supported commands, decoding steps for .res files, multiple SHA256 IOCs, and recommendations for user awareness and layered security controls.
