logo

New PowerShell-based Backdoor Found in Turkey, Strikingly Similar to MuddyWater Tools

ID: cae4bfbf-232c-4957-9325-921373a69df6

STIX ID: report--cae4bfbf-232c-4957-9325-921373a69df6

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2018-12-06

Last Modified Date: 2018-12-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro discovered a PowerShell-based backdoor, similar to MuddyWater's POWERSTATS, used in spear-phishing campaigns targeting Turkish government finance and energy organizations; malicious Office documents drop an obfuscated PowerShell DLL, establish persistence via the Run registry, and use a cloud file hosting service as an asynchronous C2/exfiltration channel. The report includes technical analysis of the backdoor, supported commands, decoding steps for .res files, multiple SHA256 IOCs, and recommendations for user awareness and layered security controls.