PowGoop is a Windows malware loader used by MuddyWater, an Iranian state-sponsored threat group subordinate to Iran’s Ministry of Intelligence and Security and also tracked as Seedworm, MERCURY, and Static Kitten. First publicly reported in July 2020, it became a principal loader in the group’s operations. PowGoop-related activity has targeted government, telecommunications, technology, oil and gas, real estate, and education organizations, particularly in the Middle East and parts of Asia.
PowGoop combines a malicious DLL loader with PowerShell-based downloading and command-execution stages. Its original execution chain abuses DLL search order hijacking and side-loading through legitimate Google Update software, with malicious components impersonating update libraries. The DLL decodes and executes externally stored, obfuscated PowerShell stages that retrieve and run additional scripts or payloads. Later variants abuse other legitimate applications and incorporate shellcode or reflectively loaded executable components before launching PowerShell.
The PowerShell stage supports HTTP beaconing, retrieval and local decryption of encrypted command-and-control instructions, and execution of operator-supplied commands. It returns command output in HTTP Cookie fields using encryption and Base64 encoding. Multi-stage decoding, script obfuscation, encrypted communications, and execution through legitimate software help conceal its activity.
PowGoop has been deployed following social-engineering attacks involving malicious Excel or PDF documents, through remote-execution tools, and in intrusion chains exploiting Microsoft Exchange CVE-2020-0688. These mechanisms stage the loader; exploitation is not an intrinsic capability of PowGoop. Its loader functionality enables installation of additional malware, while its PowerShell components provide remote command execution and transmission of command results.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Recently, Microsoft revealed that MuddyWater had been leveraging the ZeroLogon vulnerability as well (CVE-2020-1472)... CVE-2020-1472 - An elevation of privilege vulnerability that exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). | During the campaign, the group attempted to install a variant of the “PowGoop”, a malicious replacement to Google update dll. Based on PaloAlto report, “PowGoop” is a loader for a variant of Thanos ransomware with destructive capabilities.
The second vector involves exploiting CVE-2020-0688 and deploying the same payload via aspx file (WebShell). ... CVE-2020-0688 Microsoft Exchange vulnerability A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory... The exploitation provides the attacker SYSTEM level code execution privileges. | During the campaign, the group attempted to install a variant of the “PowGoop”, a malicious replacement to Google update dll. Based on PaloAlto report, “PowGoop” is a loader for a variant of Thanos ransomware with destructive capabilities.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MuddyWater actors use new variants of PowGoop malware as their main loader in malicious operations; it consists of a DLL loader and a PowerShell-based downloader.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The second vector involves exploiting CVE-2020-0688 and deploying the same payload via aspx file (WebShell).
The second vector is more in line with common MuddyWater vectors... the target receives a link to their corporate email, joined by a link to a file storing service.
MuddyWater attempts to coax their targeted victim into downloading ZIP files, containing either an Excel file with a malicious macro that communicates with the actor’s command and control server or a PDF file that drops a malicious file to the victim’s network.
A scheduled task is also generated by the attacker. This task would take part in running GoopDate.dll (PowGoop).
This PowerShell script is decoded by "goopdate.dat" ... The encrypted commands are decrypted on the victim machine and piped into a PowerShell command.
Macro - A malicious macro embedded in an excel file. The malicious piece of code installs three files used in the first stage of the infection. | A VBS file called db.vbs is downloaded from the server and stored in the Public folder.
This file was identified as an obfuscated PowerShell script
The malicious file impersonates a legitimate file that is signed as a Google Update executable file.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
128 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious loader impersonating Google Update, composed of a DLL loader and PowerShell-based downloader, used to retrieve encrypted commands from C2 infrastructure.
Primary loader used by MuddyWater that abuses DLL side-loading via a fake GoogleUpdate.exe to decode and execute a config.txt payload, unwrap an obfuscated PowerShell beacon, and begin live C2 communications. The payload contains a hardcoded C2 address and victim GUID and communicates over modified base64-encoded HTTP while masquerading under the legitimate Google Update process.
Previously used MuddyWater malware family mentioned as historical background.
A MuddyWater-associated malware/tool used in documented operations and specifically used to deliver a Thanos ransomware variant in destructive attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.