Mori is a Windows backdoor associated with the Iranian state-linked threat actor MuddyWater, also tracked as Seedworm and MERCURY. It has been used in cyber-espionage operations against government and private-sector organizations, including telecommunications, defense, local government, and oil and natural gas targets across multiple regions.
Mori has been observed as a DLL executed via regsvr32 using the DllRegisterServer export. It supports command-and-control communications using encoded JSON data and Base64, and public reporting has linked the family both to HTTP-based C2 implementations and to DNS tunneling for covert communications. The malware includes registry interaction for operational state or configuration storage, including reading, writing, and deleting values. Reported samples also used obfuscation, including large volumes of junk data embedded to hinder analysis.
Within MuddyWater intrusion chains, Mori appears as part of a broader ecosystem that has included PowGoop, Canopy/Starwhale, POWERSTATS, and other loaders and backdoors. Its observed tradecraft is consistent with post-compromise persistence and covert access in support of intelligence collection objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
This file was identified as an obfuscated PowerShell script
Examples include: “ComRAT has encrypted and stored its orchestrator code in the Registry…”, “ShadowPad maintains a configuration block and virtual file system in the Registry.”, and “QakBot can store its configuration information…under HKCU\Software\Microsoft.”
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server... Kapeka utilizes JSON objects to send and receive information from command and control nodes... Mori can use Base64 encoded JSON libraries used in C2... Remcos can serialize collected data with Protobuf.
Kapeka utilizes JSON objects to send and receive information from command and control nodes. Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Remcos can serialize collected data with Protobuf.
These components retrieve encrypted commands from a C2 server.
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor that communicates over DNS tunneling and includes a C++ DLL component executed via regsvr32 for command-and-control and follow-on tasking.
Backdoor associated in the content with DNS tunneling and high-entropy subdomain queries.
Previously used MuddyWater malware family mentioned as historical background.
A MuddyWater-associated malware/tool documented in U.S. government advisory AA22-055A.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.