Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Mori

Mori

TLP:CLEAR
Family

AI Analysis

· 22 hours ago

Executive Summary

Mori is a Windows backdoor employed by the Iranian state-sponsored group MuddyWater since early 2022. The malware offers remote control, credential theft, and data exfiltration over encrypted channels, facilitating stealthy espionage across corporate networks. Security teams must monitor for anomalous persistence mechanisms, command‑and‑control traffic, and unauthorized data transfers to mitigate potential breaches.

Enhanced Description

Mori is a Windows backdoor malware that has been attributed to the Iranian state-sponsored threat actor group MuddyWater, with evidence of operation dating back to January 2022. The family is known for its stealthy persistence and remote‑control capabilities, often leveraging legitimate system utilities and encrypted command‑and‑control channels to evade detection. Mori installs a lightweight payload that grants the adversary full read/write access to the infected host, allowing file exfiltration, credential harvesting, and lateral movement across an enterprise network. In practice, the malware creates hidden service processes with restricted visibility, injects into legitimate system binaries for privilege escalation, and communicates over TLS‑encrypted sockets to a hardened command‑and‑control domain. Analysts observing traffic have noted a typical pattern of daily activity: initial reconnaissance scans, discovery of shared resources, followed by data staging and exfiltration of sensitive documents or credential dumps. Recent reports from DHS's CISA advisory (AA22-055A) and CYBERCOM Iranian Intel Cyber indicate Mori’s use in supply‑chain compromise scenarios, where the backdoor is deployed after initial footholds are established through spear‑phishing or compromised vendor platforms. The operation combines standard RAT behaviors with a modular architecture that allows the malware authors to load additional modules on demand—such as keyloggers, screenshot capture utilities, and ransomware payloads—without altering the core installer. This flexibility makes Mori capable of both espionage (information theft) and destructive actions, providing MuddyWater with an adaptable toolkit for long‑term persistence, lateral movement, and data exfiltration in targeted environments.

Key Capabilities

  • Command and control via TLS‑encrypted sockets
  • Persistence through hidden service processes and auto‑start entries
  • Privilege escalation through process injection or masquerading of system binaries
  • Credential harvesting from local SAM/Active Directory
  • Encrypted file staging and exfiltration
  • Remote code execution
  • Keylogging and screenshot capture modules
  • Lateral movement across network shares
  • Scheduled task creation for persistence

Description

Mori is a backdoor that has been used by MuddyWater since at least January 2022.(Citation: DHS CISA AA22-055A MuddyWater February 2022)(Citation: CYBERCOM Iranian Intel Cyber January 2022)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.