Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware MURKYTOP

MURKYTOP

TLP:CLEAR
Family

AI Analysis

· 9 hours ago

Executive Summary

MURKYTOP is a reconnaissance tool used by the Iranian‑backed threat group Leviathan to map target Windows environments through passive scanning and system discovery. The malware collects network, host, and account information, feeding later stages of an APT campaign aimed at exploitation or credential theft. Its presence indicates a high‑stage malicious operation that warrants immediate investigation.

Enhanced Description

MURKYTOP is a Windows‑based reconnaissance tool employed by the threat group known as Leviathan, an advanced persistent threat believed to have ties to Iranian state sponsors and frequently targeting the Middle East and energy sectors. Classified as part of a broader malware family operated by Leviathan, MURKYTOP was first identified in FireEye’s Periscope report released in March 2018, but has since been observed on multiple targets across various industries. The tool operates similarly to many covert data‑collection utilities, initiating passive scans against the victim network to identify active hosts, IP ranges, and open ports. It harvests system details such as OS version, machine name, and service metadata, then performs DNS lookups and enumeration of domain trust relationships. While no code samples are publicly available, analysts suspect that MURKYTOP may also include modules for capturing stored credentials from local security policies or from Windows Credential Manager to aid future lateral‑movement attempts. Operationally, MURKYTOP does not appear to deliver payloads directly; instead it focuses on building a detailed map of the target environment. By compiling this information in an organized data lake or via C2 channels, Leviathan can later launch more directed attacks, such as credential dumping or exploitation of discovered services. The intelligence gathered thus accelerates subsequent stages of the ATT&CK workflow from Reconnaissance to Execution. Because MURKYTOP is a reconnaissance phase utility rather than a destructive payload, detection largely revolves around monitoring unusual network scanning patterns, abnormal process creation for known recon executables, and anomalous outbound connections that match known C2 signatures. Security teams should flag any unfamiliar tools performing extensive port or domain enumeration on corporate assets.

Key Capabilities

  • Network range discovery
  • Active host enumeration via ping/ICMP and port scanning
  • Operating system version and service information gathering
  • DNS queries and domain trust relationship mapping
  • Credential harvesting from Windows Credential Manager or local security policies (inferred)
  • Data exfiltration to command‑and‑control endpoints

ATT&CK Techniques

T1018 Remote System Discovery
T1046 Network Service Scanning
T1087 Account Enumeration
T1059 PowerShell
T1105 Ingress Tool Transfer
T1027 Obfuscated Files or Information

Recommended Actions

  • Deploy network segmentation controls to limit internal reconnaissance traffic.
  • Implement endpoint detection that flags unusual port scanning or DNS enumeration activity on Windows hosts.
  • Block outbound connections from identified MURKYTOP IPs and domains, using threat intelligence feeds.
  • Correlate logs for abnormal SMB/SMB2 usage or LDAP queries indicating account enumeration.
  • Enable host hardening: disable local credential storage mechanisms where possible.
  • Conduct threat hunting exercises focusing on the presence of recon tools within internal networks.

Suggested Tags

Leviathan
APT40
Reconnaissance
Windows malware
FireEye Periscope
MURKYTOP
APT28
Iran state-sponsored

Confidence Assessment

The information is derived from a single external report (FireEye Periscope March 2018) with no publicly released sample or detailed technical analysis. While the attribution to Leviathan and Windows execution context are confirmed, specific behaviors such as credential dumping modules remain inferred. Confidence in operational capabilities is moderate; however, the lack of observable indicators of compromise reduces actionable insight without supplemental data.

Description

MURKYTOP is a reconnaissance tool used by Leviathan. (Citation: FireEye Periscope March 2018)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.