Mori is a Windows backdoor used by MuddyWater, also known as Seedworm, an Iranian state-sponsored cyberespionage group subordinate to Iran’s Ministry of Intelligence and Security. Mori uses DNS tunneling to communicate with command-and-control infrastructure. An analyzed C++ DLL implementation also supports HTTP communication over IPv4 or IPv6 and uses Base64 encoding and JSON for command-and-control data handling.
Mori can execute through the Windows Regsvr32 utility using its DLL registration export. It reads and writes Windows Registry data and can delete Registry values. Evasion techniques include encrypted strings used to resolve networking APIs and binary padding with approximately 200 MB of junk resource data. The analyzed implementation creates a mutex when executed.
Mori forms part of MuddyWater’s malware arsenal for operations against government and private-sector organizations. The group’s targeting spans Asia, Africa, Europe, and North America, including telecommunications, defense, local government, and oil and natural gas organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MuddyWater also uses the Mori backdoor that uses Domain Name System tunneling to communicate with the group’s C2 infrastructure.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
This file was identified as an obfuscated PowerShell script
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server... Kapeka utilizes JSON objects to send and receive information from command and control nodes... Mori can use Base64 encoded JSON libraries used in C2... Remcos can serialize collected data with Protobuf.
Kapeka utilizes JSON objects to send and receive information from command and control nodes. Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Remcos can serialize collected data with Protobuf.
These components retrieve encrypted commands from a C2 server.
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor that communicates over DNS tunneling and includes a C++ DLL component executed via regsvr32 for command-and-control and follow-on tasking.
Backdoor associated in the content with DNS tunneling and high-entropy subdomain queries.
Previously used MuddyWater malware family mentioned as historical background.
A MuddyWater-associated malware/tool documented in U.S. government advisory AA22-055A.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.