Mori is a backdoor associated with the Iranian state-sponsored MuddyWater/Seedworm intrusion set, which public reporting and joint government advisories attribute to Iran’s Ministry of Intelligence and Security (MOIS). The malware has been documented in MuddyWater campaigns alongside PowGoop, Small Sieve, Canopy/Starwhale, and POWERSTATS. Mori is described as a C++ DLL backdoor that uses DNS tunneling to communicate with MuddyWater command-and-control infrastructure, including use of Base64-encoded JSON in C2 communications. Reported execution includes DLL execution via regsvr32.exe. A documented sample, FML.dll, was executed with regsvr32.exe and contained approximately 200 MB of junk data in a resource directory for obfuscation. Mori can read data from and write data to Windows Registry locations including HKLM\Software\NFC\IPA and HKLM\Software\NFC, and can delete Registry values. Reporting notes DNS requests with high-entropy subdomains as a host/network indicator consistent with Mori DNS-tunneling activity. Mori samples were among artifacts uploaded by U.S. Cyber Command, and AA22-055A formally documented Mori as part of MuddyWater tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Previous campaigns have employed malware families such as PowGoop, Small Sieve, Mori, POWERSTATS, Canopy/Starwhale, and more recently MuddyViper and GhostBackDoor variants.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Examples include: “ComRAT has encrypted and stored its orchestrator code in the Registry…”, “ShadowPad maintains a configuration block and virtual file system in the Registry.”, and “QakBot can store its configuration information…under HKCU\Software\Microsoft.”
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
AppleSeed can call regsvr32.exe for execution. APT19 used Regsvr32 to bypass application control techniques. APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. ... Raspberry Robin uses regsvr32.exe execution without any command line parameters for command and control requests to IP addresses associated with Tor nodes.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server... Kapeka utilizes JSON objects to send and receive information from command and control nodes... Mori can use Base64 encoded JSON libraries used in C2... Remcos can serialize collected data with Protobuf.
Kapeka utilizes JSON objects to send and receive information from command and control nodes. Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Remcos can serialize collected data with Protobuf.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor associated in the content with DNS tunneling and high-entropy subdomain queries.
Previously used MuddyWater malware family mentioned as historical background.
A MuddyWater-associated malware/tool documented in U.S. government advisory AA22-055A.
A backdoor sample associated with MuddyWater operations and included among malware samples highlighted by USCYBERCOM.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.