Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 4 actors

ForeLord

FORELORD is a previously unobserved remote access trojan (RAT) identified by Secureworks CTU and associated with the Iranian state-linked espionage group COBALT ULSTER, also known as MuddyWater, Seedworm, TEMP.Zagros, and Static Kitten. CTU observed it in late 2019 and early 2020 in spearphishing campaigns targeting non-governmental organizations and Middle Eastern government entities; broader COBALT ULSTER activity in the same period also targeted government organizations in Turkey, Jordan, and Iraq, as well as intergovernmental organizations and entities in Georgia and Azerbaijan. Delivery involved ZIP archives containing malicious Excel files with obfuscated macros. In the FORELORD infection chain, the Excel file used cmd.exe to run a batch script (tt.bat) that established persistence via a registry key for restart, and a PowerShell script then used rundll32.exe to execute the FORELORD payload as Exchange.dll. FORELORD uses a DNS-based command-and-control protocol over DNS TXT records, including DNS tunneling through legitimate resolvers to actor-controlled nameservers. CTU reported that its protocol uses the response string "lordlordlordlord" to acknowledge message reception. By pivoting on this C2 protocol, CTU identified 14 additional domains possibly registered by COBALT ULSTER. Post-compromise activity observed alongside this intrusion set included credential dumping and validation using PASS32.dll, PASS64.dll, PasswordDumper.exe, Caller.dll (a Mimikatz variant), and CredNinja.ps1, as well as use of Secure Socket Funneling (ssf.exe) to create a TLS tunnel and port forwarding, potentially enabling RDP access.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
MuddyWater

In late 2019/early 2020, CTU researchers observed COBALT ULSTER targeting non-governmental organizations (NGOs) and Middle Eastern governments using malware CTU researchers named FORELORD based on behavioral aspects of the malware's C2 communications.

via secureworks threat profilessecureworks.com
STAC 1171

"In late 2019/early 2020, CTU researchers observed COBALT ULSTER targeting non-governmental organizations (NGOs) and Middle Eastern governments using malware CTU researchers named FORELORD based on behavioral aspects of the malware's C2 communications."

via secureworks threat profilessecureworks.com
ENT-11

"In late 2019/early 2020, CTU researchers observed COBALT ULSTER targeting non-governmental organizations (NGOs) and Middle Eastern governments using malware CTU researchers named FORELORD based on behavioral aspects of the malware's C2 communications."

via secureworks threat profilessecureworks.com
MuddyCoast

"In late 2019/early 2020, CTU researchers observed COBALT ULSTER targeting non-governmental organizations (NGOs) and Middle Eastern governments using malware CTU researchers named FORELORD based on behavioral aspects of the malware's C2 communications."

via secureworks threat profilessecureworks.com
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1583.006Web ServicesEvidence1

"COBALT ULSTER leverages compromised infrastructure for command and control."

Initial Access

2 techniques
T1566PhishingEvidence1

The group uses macro-laden phishing documents...

T1566.001Spearphishing AttachmentEvidence1

"The group uses macro-laden phishing documents..."

Execution

1 technique
T1204.002Malicious FileEvidence1

The group uses macro-laden phishing documents...

Stealth

1 technique
T1036MasqueradingEvidence1

"The threat actors inject false flags into code associated with their operations, likely to confuse security researchers..."

Command and Control

1 technique
T1071Application Layer ProtocolEvidence1

COBALT ULSTER leverages compromised infrastructure for command and control.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution4

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.