Executive Summary
MURKYTOP is a reconnaissance tool used by the Iranian‑backed threat group Leviathan to map target Windows environments through passive scanning and system discovery. The malware collects network, host, and account information, feeding later stages of an APT campaign aimed at exploitation or credential theft. Its presence indicates a high‑stage malicious operation that warrants immediate investigation.
Enhanced Description
MURKYTOP is a Windows‑based reconnaissance tool employed by the threat group known as Leviathan, an advanced persistent threat believed to have ties to Iranian state sponsors and frequently targeting the Middle East and energy sectors. Classified as part of a broader malware family operated by Leviathan, MURKYTOP was first identified in FireEye’s Periscope report released in March 2018, but has since been observed on multiple targets across various industries. The tool operates similarly to many covert data‑collection utilities, initiating passive scans against the victim network to identify active hosts, IP ranges, and open ports. It harvests system details such as OS version, machine name, and service metadata, then performs DNS lookups and enumeration of domain trust relationships. While no code samples are publicly available, analysts suspect that MURKYTOP may also include modules for capturing stored credentials from local security policies or from Windows Credential Manager to aid future lateral‑movement attempts. Operationally, MURKYTOP does not appear to deliver payloads directly; instead it focuses on building a detailed map of the target environment. By compiling this information in an organized data lake or via C2 channels, Leviathan can later launch more directed attacks, such as credential dumping or exploitation of discovered services. The intelligence gathered thus accelerates subsequent stages of the ATT&CK workflow from Reconnaissance to Execution. Because MURKYTOP is a reconnaissance phase utility rather than a destructive payload, detection largely revolves around monitoring unusual network scanning patterns, abnormal process creation for known recon executables, and anomalous outbound connections that match known C2 signatures. Security teams should flag any unfamiliar tools performing extensive port or domain enumeration on corporate assets.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The information is derived from a single external report (FireEye Periscope March 2018) with no publicly released sample or detailed technical analysis. While the attribution to Leviathan and Windows execution context are confirmed, specific behaviors such as credential dumping modules remain inferred. Confidence in operational capabilities is moderate; however, the lack of observable indicators of compromise reduces actionable insight without supplemental data.
MURKYTOP is a reconnaissance tool used by Leviathan. (Citation: FireEye Periscope March 2018)