Suspicious PowerShell Host and Locale Reconnaissance via MuddyWater Tsundere Botnet

PremiumReviewedSigma · Medium · v1
Category
process_creation
Author
HuntRule
Published
2026-09-22
Updated
2026-09-22

ATT&CK techniques

Execution → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects PowerShell enumerating the video controller hardware together with the installed UI culture in a single command. This combined host and locale fingerprinting is used by the MuddyWater Tsundere botnet to profile victims and filter sandboxes before staging its Ethereum-based command and control. Such reconnaissance precedes payload delivery and warrants investigation.

Related detections9 linkedT1059.001 — drag to rearrange
Suspicious Encoded PowerShell Host Reconnaissance via Get-ComputerInfo via ps_script
Malicious PowerShell StreamReader WebRequest Download Cradle
Suspicious PowerShell UTF8 OutputEncoding Command Wrapper
Malicious PowerShell Clipboard Script Execution via ScriptBlock Create
Malicious ClickFix MSI Download and Execution via PowerShell
Suspicious System Reconnaissance Output Redirected to Temp rad File
Suspicious PowerShell Download Cradle via Net.WebClient DownloadFile
Suspicious Script Host Launching PowerShell from Fattura Named JScript File (via process_creation)
Malicious Renamed Python Interpreter svchostc Executing Script (via process_creation)
Suspicious PowerShell Host and Locale Reconnaissance via MuddyWater Tsundere Botnet
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.