S0591Windows

S0591ConnectWise

Platforms
1
ATT&CK
14.1
References
3

Description

[ConnectWise](https://attack.mitre.org/software/S0591) is a legitimate remote administration tool that has been used since at least 2016 by threat actors including [MuddyWater](https://attack.mitre.org/groups/G0069) and [GOLD SOUTHFIELD](https://attack.mitre.org/groups/G0115) to connect to and conduct lateral movement in target environments.(Citation: Anomali Static Kitten February 2021)(Citation: Trend Micro Muddy Water March 2021)

Platforms· 1

Windows

Attributed to2

TypeTargetConfidenceTier
GroupMuddyWaterg0069100%live
GroupGOLD SOUTHFIELDg0115100%live

References

  1. https://attack.mitre.org/software/S0591
  2. https://www.anomali.com/blog/probable-iranian-cyber-actors-static-kitten-conducting-cyberespionage-campaign-targeting-uae-and-kuwait-government-agencies
  3. https://www.trendmicro.com/en_us/research/21/c/earth-vetala---muddywater-continues-to-target-organizations-in-t.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
RemoteUtilities
Software
Out1
Software
Waterbear
Software
NETWIRE
Software
StrifeWater
Software
Explosive
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.