STATS Backdoor Family
Beginning with POWERSTATS v1 in 2011, STATS is a family of backdoor malware created and used by the MuddyWater advanced persistent threat group for use in their campaigns against governmental, telecoms and transportation organisations.
Summary
Beginning with POWERSTATS v1 in 2011, STATS is a family of backdoor malware created and used by the MuddyWater advanced persistent threat group for use in their campaigns against governmental, telecoms and transportation organisations.
Affected platforms
The following platforms are known to be affected:
Threat details
As with most MuddyWater malware, the STATS family are delivered as malicious Microsoft Office attachments distributed via sophisticated spear-phishing attacks. When opened, these attachments will execute embedded macros containing base64 encoded PowerShell commands, which in turn extract STATS.
Once installed, all STATS variants will collect system information and send it to a command and control (C2) server. They will then install a number of post-exploitation tools including Mimikatz, Meterpreter and Empire before awaiting further instructions. At the time of publication there are four observed STATS family variants:
- CLOUDSTATS - PowerShell-based variant. Uses cloud file hosting platforms for command and control communications.
- DELPHSTATS - Delphi-based variant. Typically used to retrieve payloads from a MuddyWater controlled C2 server before executing them.
- POWERSTATS - Primary STATS variant used in most MuddyWater campaigns. Currently on version 3.
- SHARPSTATS - .NET-based variant. Can locate and extract target files and folders.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:50 pm