Starwhale, also known as Canopy, is a Windows-based MuddyWater malware family used in Iranian state-aligned espionage operations. It has been associated with campaigns targeting government and private-sector organizations, including telecommunications, defense, local government, and oil and natural gas entities across Asia, Africa, Europe, and North America. The malware has commonly been delivered through spearphishing emails carrying malicious Microsoft Excel attachments that rely on user macro execution and embedded Windows Script File components.
Starwhale functions as a script-based backdoor that performs host discovery, command execution, persistence, and data exfiltration. Observed samples collect basic victim information such as local IP address, computer name, and username, encode that data, and transmit it to command-and-control infrastructure over HTTP POST. The malware receives commands from its controller and executes them through the Windows command interpreter, capturing command output locally before encoding and returning the results over the same command-and-control channel. Reported samples also stage collected output in a local text file prior to exfiltration.
Persistence has been achieved through Windows service creation and startup execution of dropped script components. Starwhale has used VBScript functionality, including GetRef, as part of its execution and persistence logic, and has been observed creating an auto-start service that launches the Windows Script Host under LocalSystem. In documented delivery chains, malicious Excel documents decode and drop script payloads that maintain persistence and continue collection and exfiltration activity.
The malware is closely linked to MuddyWater, a threat actor publicly associated with Iran’s Ministry of Intelligence and Security. Within MuddyWater operations, Starwhale has appeared alongside other families such as PowGoop, Small Sieve, Mori, and POWERSTATS as part of broader intrusion sets focused on long-term access, espionage, and theft of victim system data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Two malicious Microsoft Excel spreadsheets were identified as Canopy malware (also known as Starwhale) that contained macros and two encoded Windows script files, which maintain persistence and collect and exfiltrate the victim's system data to a command and control (C2).
"STARWHALE communicates with its C2 server, which is hardcoded in the malware... The C2 server will then respond with a command meant to be executed via cmd.exe"
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The latest campaigns undertaken by the hacking crew involve the use of malware-laced documents delivered via phishing messages to deploy a remote access trojan called SloughRAT
MuddyWater attempts to coax their targeted victim into downloading ZIP files, containing either an Excel file with a malicious macro that communicates with the actor’s command and control server or a PDF file that drops a malicious file to the victim’s network.
The obfuscated Trojan also attempts to execute arbitrary code and commands received from its command and control servers... one written in Visual Basic during 2021-2022 and one written in JavaScript in 2019-2020, which also downloads and runs arbitrary commands on the victim's system.
If the payload contains one of these strings, it will parse the command-line scripts for execution using the command below: "cmd.exe /c [decoded command scripts]"
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
cmd.exe /c >> %temp%\h.txt Select * from Win32_IP4RouteTable
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
59 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware delivered through spear-phishing attachments, including malicious Excel files with VBA macros and encoded Windows Script Files that decode and install embedded payloads.
Previously used MuddyWater malware family mentioned as historical background.
A MuddyWater-associated malware/tool documented in U.S. government advisory AA22-055A.
Uses the VBScript GetRef function as part of persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.