PowGoop — Malware Profile
PowGoop is a loader that consists of a DLL loader and a PowerShell-based downloader; it has been used by MuddyWater as their main loader.
MITRE ATT&CK techniques (8)
- T1036 Masquerading
- T1036.005 Match Legitimate Resource Name or Location
- T1059.001 PowerShell
- T1071.001 Web Protocols
- T1132.002 Non-Standard Encoding
- T1140 Deobfuscate/Decode Files or Information
- T1573 Encrypted Channel
- T1574.001 DLL