PowGoop

Malware updated 6 months ago (2024-05-04T19:19:10.102Z)
Download STIX
Preview STIX
PowGoop is a malicious software (malware) employed by MuddyWater actors, an Iranian cyber threat group also known as TEMP.Zagros. This malware primarily functions as a loader in the group's nefarious operations and includes a DLL loader and a PowerShell-based downloader. The hackers have been observed using multiple malware sets including PowGoop, Small Sieve, Canopy/Starwhale, Mori, and POWERSTATS for loading malware, backdoor access, persistence, and exfiltration. They deploy sophisticated techniques such as side-loading DLLs to deceive legitimate programs into running malware and obfuscating PowerShell scripts to hide command and control (C2) functions. The Federal Bureau of Investigation (FBI), Cybersecurity & Infrastructure Security Agency (CISA), Cyber National Mission Force (CNMF), and National Cyber Security Centre UK (NCSC-UK) have noted recent use of various malware variants by MuddyWater actors. These include new versions of PowGoop, among others, as part of their malicious activities. In spear-phishing operations, the group has consistently updated its toolkit over the years, leveraging malware like POWERSTATS, POWGOOP, and MORIAGENT. Iranian hackers have utilized the PowGoop downloader, delivered via phishing emails, and exploited publicly known Microsoft Exchange server vulnerabilities to deliver Thanos ransomware. Open-source cyber research discovered PowGoop Loader variants in compromised networks, which de-obfuscate a PowerShell script enabling attacker command and control functions. Additional PowGoop variants, including C2 Beacon, Loader, and DLL Side-Loading variants, have been identified. These leverage different naming conventions, such as libpcre2-8-0.dll and vcruntime140.dll, to evade antivirus and manual detection, furthering their potential for espionage and ransomware activities.
Description last updated: 2024-05-04T18:55:24.658Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Phishing
Ransomware
Downloader
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the PowGoop Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more