1200KM / tool
Out1 — Attack Tool
Out1 is a remote access tool written in python and used by MuddyWater since at least 2021.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Out1
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- MuddyWater · G0069 · Pinned relationship source (relationship--3574efdf-c9f0-4515-806e-a9a5437be02a)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1005 · Data from Local System · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1114.001 · Local Email Collection · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- File Modification · DC0061
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Creation · DC0032
- Script Execution · DC0029
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.