POWERSTATS, also known as Powermud, is a PowerShell-based backdoor for Windows associated with MuddyWater, an Iranian state-sponsored espionage group subordinate to Iran’s Ministry of Intelligence and Security. It provides persistent access to compromised systems and supports reconnaissance and data theft. POWERSTATS has been deployed in campaigns targeting government entities and telecommunications organizations, including targets in Tajikistan and Turkey, within MuddyWater’s broader focus on the Middle East and Central Asia.
Delivery chains use malicious Office documents, macros, and impersonation lures. A documented campaign combined exploitation of CVE-2017-0199 with macro-enabled documents retrieved from compromised servers to extract and execute POWERSTATS. Execution and staging involve PowerShell, encoded VBScript, JavaScript, and the Windows HTML Application Host, with multiple layers of script obfuscation and runtime deobfuscation.
POWERSTATS establishes persistence through scheduled tasks and uses Base64-encoded command-and-control traffic. Its capabilities include capturing screenshots, enumerating running processes, identifying the current username, collecting IP addresses, network adapter configuration and domain information, and uploading files from compromised hosts. It can also execute additional payloads and issue PowerShell commands to delete files across multiple local drives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Clearsky has detected new and advanced attack vector used by MuddyWater to target governmental entities and the telecommunication sector. Notably, the TTP includes decoy documents exploiting CVE-2017-0199 as the first stage of the attack. | These files contain segments of the malicious code used to extract the POWERSTATS malware.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These files contain segments of the malicious code used to extract the POWERSTATS malware.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
98 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
98 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PowerShell-based backdoor used to maintain persistent access on victim systems.
A proprietary PowerShell backdoor used by MuddyWater for cyber-espionage. It performs host and network reconnaissance, remote code execution, file upload/download via C2, anti-analysis checks, destructive actions such as deleting files or disabling the device when analysis tools are detected, screenshot capture, and disabling Microsoft Office security features.
Previously used MuddyWater malware family mentioned as historical background.
A backdoor/tool used in early MuddyWater-attributed operations against Middle East organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.