PowGoop is a Windows malware family used primarily by the Iranian state-aligned threat actor MuddyWater, also tracked as Seedworm, Static Kitten, MERCURY, and related aliases. It is best characterized as a loader that abuses DLL side-loading and DLL search order hijacking, most notably by impersonating components of Google Update so that a legitimate executable loads a malicious DLL. The malicious DLL typically launches a multi-stage PowerShell chain from external encoded or obfuscated files, enabling command execution, retrieval of additional payloads, and command-and-control communications while blending activity under a benign-looking process lineage.
Operational reporting consistently links PowGoop to MuddyWater espionage activity against government and private-sector organizations across the Middle East, Asia, Africa, Europe, and North America, including telecommunications, defense, local government, oil and natural gas, technology, education, and related sectors. Multiple investigations describe PowGoop as a core MuddyWater loader in use since at least 2020, with ongoing maintenance and newer variants that side-load through additional legitimate applications and load shellcode or PE-like intermediary components before executing PowerShell backdoors.
PowGoop commonly consists of a hijacked DLL loader plus PowerShell-based downloader or beacon stages. Documented behavior includes spawning Rundll32 to invoke exported functions in the malicious DLL, decoding staged content from auxiliary files, executing PowerShell commands, receiving encrypted tasking from command-and-control infrastructure, and exfiltrating command output over HTTP using obfuscation and encoding. Some variants are described as fully functional PowerShell backdoors disguised with benign extensions. Reporting also notes that PowGoop can install or retrieve additional malware and tooling, and it has been observed alongside other MuddyWater malware families such as Mori, Canopy or Starwhale, Small Sieve, and POWERSTATS.
Delivery and intrusion context associated with PowGoop includes spearphishing campaigns using archive attachments, malicious Excel macro lures, PDF-based droppers, and in some cases deployment after exploitation of public-facing Microsoft Exchange vulnerabilities. In several campaigns, PowGoop was packaged with legitimate binaries inside archives to facilitate side-loading. It has also been observed after remote execution activity and as part of broader post-compromise tradecraft involving tunneling tools and credential theft by MuddyWater operators.
PowGoop has also been discussed in connection with a 2020 MuddyWater campaign targeting Israeli organizations in which operators attempted to deploy a PowGoop variant assessed by some researchers as a loader for a destructive Thanos ransomware variant. However, broader reporting on PowGoop more consistently supports its role as a loader and PowerShell-based staging mechanism for espionage-oriented operations rather than ransomware itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Recently, Microsoft revealed that MuddyWater had been leveraging the ZeroLogon vulnerability as well (CVE-2020-1472)... CVE-2020-1472 - An elevation of privilege vulnerability that exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). | During the campaign, the group attempted to install a variant of the “PowGoop”, a malicious replacement to Google update dll. Based on PaloAlto report, “PowGoop” is a loader for a variant of Thanos ransomware with destructive capabilities.
The second vector involves exploiting CVE-2020-0688 and deploying the same payload via aspx file (WebShell). ... CVE-2020-0688 Microsoft Exchange vulnerability A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory... The exploitation provides the attacker SYSTEM level code execution privileges. | During the campaign, the group attempted to install a variant of the “PowGoop”, a malicious replacement to Google update dll. Based on PaloAlto report, “PowGoop” is a loader for a variant of Thanos ransomware with destructive capabilities.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In February 2022, CISA published indicators that signal MuddyWater activity, including the IP address 164.132.237[.]65. In March 2022, this address was observed to be a MuddyC2Go server. It was previously associated with PowGoop.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The second vector involves exploiting CVE-2020-0688 and deploying the same payload via aspx file (WebShell).
The second vector is more in line with common MuddyWater vectors... the target receives a link to their corporate email, joined by a link to a file storing service.
MuddyWater attempts to coax their targeted victim into downloading ZIP files, containing either an Excel file with a malicious macro that communicates with the actor’s command and control server or a PDF file that drops a malicious file to the victim’s network.
A scheduled task is also generated by the attacker. This task would take part in running GoopDate.dll (PowGoop).
This PowerShell script is decoded by "goopdate.dat" ... The encrypted commands are decrypted on the victim machine and piped into a PowerShell command.
Macro - A malicious macro embedded in an excel file. The malicious piece of code installs three files used in the first stage of the infection. | A VBS file called db.vbs is downloaded from the server and stored in the Public folder.
This file was identified as an obfuscated PowerShell script
The malicious file impersonates a legitimate file that is signed as a Google Update executable file.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
These components retrieve encrypted commands from a C2 server.
Seedworm was also observed setting up tunnels to its own infrastructure using Secure Sockets Funneling and Chisel. These tools allow the attackers to configure local and remote port forwarding
during PowGoop activity, we also observed the attackers downloading tools and some unknown content from GitHub repos
128 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious loader impersonating Google Update, composed of a DLL loader and PowerShell-based downloader, used to retrieve encrypted commands from C2 infrastructure.
Primary loader used by MuddyWater that abuses DLL side-loading via a fake GoogleUpdate.exe to decode and execute a config.txt payload, unwrap an obfuscated PowerShell beacon, and begin live C2 communications. The payload contains a hardcoded C2 address and victim GUID and communicates over modified base64-encoded HTTP while masquerading under the legitimate Google Update process.
Previously used MuddyWater malware family mentioned as historical background.
A MuddyWater-associated malware/tool used in documented operations and specifically used to deliver a Thanos ransomware variant in destructive attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.