Researchers discovered a “Blackwater” malware campaign that is linked to the known MuddyWater APT, bypassing security controls and installing a backdoor on the victim’s computer using MuddyWater’s techniques and procedures (TTPs).
MuddyWater is found in several different cyberattacks targeting organizations in Pakistan, Turkey, and Tajikistan using multiple social engineering methods to trick victims into enabling macros and activating the payload.
The Blackwater campaign is believed to be a new arsenal of the MuddyWater APT, as activities show that hackers are implementing many tactics within it to evade endpoint detection .
The hackers who use the Obfuscated VBA script to create the VBA script activated a PowerShell stager.
Backwater also used a FruityC2 agent script, an open-source framework on GitHub, allowing the PowerShell stager to communicate with the C2 server to control the host machine.

Researchers discovered a weaponized document being sent to victims via “ phishing ” emails with a creation date of April 23.
Once the victims open the malicious document, it required the user to activate the macro titled “BlackWater.bas”
The hackers also used an anti-reverse technique protecting the macro with a password, if a user attempted to view the macro in Visual Basic.
According to Talos Research, “The macro contains a PowerShell script for the registry key” “Run”
“KCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Run \ SystemTextEncoding”
The script then names the file “\ProgramData\SysTextEnc.ini” every 300 seconds. The clear text version of SysTextEnc.ini appears to be a lightweight stager.
This PowerShell agent was previously used by the creators of MuddyWater when targeting Kurdish political groups and organizations in Turkey.
In the Blackwater campaign, hackers have made some small changes, such as changing variable names to avoid Yara detection and sending command results to the C2 at the URL address instead of logging to a file.
Finally, the PowerShell script will scan the victim's machine for the following information.
- The name of the operating system (i.e., the machine name)
- Operating system architecture
- The subtitle of the operating system
- The domain of the computer system
- The username of the computer system
- Public IP address of the computer
After listing all the information, it proposes the post request URL to a base64-encoded C2, while in previous versions this information was recorded in a text file.
