STARWHALE, also known as Canopy, is a VBScript-based Windows backdoor used by MuddyWater, an Iranian state-sponsored threat actor subordinate to Iran’s Ministry of Intelligence and Security. It has also been observed in activity tracked as UNC3313. STARWHALE supports host reconnaissance, remote command execution, and data exfiltration in cyberespionage operations. MuddyWater’s broader targeting includes government and private-sector organizations in telecommunications, defense, local government, and oil and natural gas across Asia, Africa, Europe, and North America.
STARWHALE is distributed through spearphishing attachments, including malicious Microsoft Excel workbooks. When victims enable embedded VBA macros, the macros decode and install Windows Script File payloads. Observed deployments maintain persistence through startup-folder scripts or an automatically starting Windows service. The malware can dynamically resolve VBScript functions using GetRef. It collects the infected system’s IP address, computer name, and username, encodes this information, and transmits it to command-and-control infrastructure through HTTP POST requests. It receives commands from its controller, executes them through the Windows command interpreter, stages command output locally, and returns encoded results over the same communications channel. Observed samples use hexadecimal or custom encoding for collected data and command output.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MuddyWater also uses Canopy/Starwhale malware, likely distributed via spearphishing emails with targeted attachments.
"STARWHALE communicates with its C2 server, which is hardcoded in the malware... The C2 server will then respond with a command meant to be executed via cmd.exe"
19 distinct techniques documented for this family, organized by ATT&CK tactic.
If the payload contains one of these strings, it will parse the command-line scripts for execution using the command below: "cmd.exe /c [decoded command scripts]"
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
cmd.exe /c >> %temp%\h.txt Select * from Win32_IP4RouteTable
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
59 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware delivered through spear-phishing attachments, including malicious Excel files with VBA macros and encoded Windows Script Files that decode and install embedded payloads.
Previously used MuddyWater malware family mentioned as historical background.
A MuddyWater-associated malware/tool documented in U.S. government advisory AA22-055A.
Uses the VBScript GetRef function as part of persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.