POWERSTATS is a Windows backdoor associated with MuddyWater operations. It is heavily script-based and relies on PowerShell for execution and obfuscation, while also using JavaScript, VBScript, and mshta as auxiliary execution mechanisms. The malware establishes persistence through Windows Scheduled Tasks and can execute additional payloads through signed Windows utilities, reflecting a strong emphasis on living-off-the-land tradecraft and defense evasion.
Functionally, POWERSTATS supports host reconnaissance and post-compromise collection. Documented capabilities include identifying the current username, enumerating running processes, and gathering local network configuration details such as IP addressing, adapter configuration, and domain information. It can capture screenshots from compromised systems and upload files from infected hosts, indicating both surveillance and data theft utility. Its command-and-control traffic has been observed encoded with Base64, and it includes deobfuscation functionality for its main backdoor logic.
POWERSTATS has also been associated with destructive behavior: variants or related activity have used PowerShell commands to delete files across multiple local drives. Overall, POWERSTATS is best characterized as a PowerShell-centric Windows backdoor used for persistence, reconnaissance, collection, exfiltration, and stealthy execution in intrusions attributed to MuddyWater.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Clearsky has detected new and advanced attack vector used by MuddyWater to target governmental entities and the telecommunication sector. Notably, the TTP includes decoy documents exploiting CVE-2017-0199 as the first stage of the attack... Attack Vector 2 – CVE-2017-0199 ... MuddyWater has not used this TTP previously. | These files contain segments of the malicious code used to extract the POWERSTATS malware.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
After opening the document, a VBS file is created. It is encoded with multiple VBE, JavaScript, and Base64 layers; similar to previous attack vectors by MuddyWater. | Attack Vector 1 – malicious macro... using the group's classic attack vector – a malicious VBA macro.
This is the first time MuddyWater has used these two vectors in conjunction... Opening the file leverages CVE-2017-0199 and sends a request to the hacked server. | Attack Vector 2 – CVE-2017-0199... If the victim confirms, the vulnerability will activate, and the Word software will communicate to the C2 server.
Malicious macro-embedded document used to launch an Excel process and a PowerShell command as first stage. | In the first stage of the operation the attackers deliver a macro-embedded document. Depending on each sample, the content of document is either a fake resume application, or a letter from the Ministry of Justice in Lebanon or Saudi Arabia.
Frankenstein has used PowerShell to run a series of base64-encoded commands, that acted as a stager and enumerated hosts.
The executable is written in Delphi and packed with UPX, contains anti-analysis techniques, and seems to be impersonating a cellular networking tool.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload.
APT29 has use mshta to execute malicious scripts on a compromised host... APT32 has used mshta.exe for code execution... APT38 has used a renamed version of mshta.exe to execute malicious HTML files... FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Finally, the aforementioned ID.dat file is updated... The second executable starts by checking the internet connectivity. It sends a request to google.com... Then, it will POST the file containing the system details to 185.117.75[.]116.php... Returning to the main executable, a request is sent to googleads.hopto[.]org with the victim’s unique ID.
98 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
96 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PowerShell-based backdoor used to maintain persistent access on victim systems.
A proprietary PowerShell backdoor used by MuddyWater for cyber-espionage. It performs host and network reconnaissance, remote code execution, file upload/download via C2, anti-analysis checks, destructive actions such as deleting files or disabling the device when analysis tools are detected, screenshot capture, and disabling Microsoft Office security features.
Previously used MuddyWater malware family mentioned as historical background.
A backdoor/tool used in early MuddyWater-attributed operations against Middle East organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.