Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks

In March 2024, a new phishing attempt was attributed to the Iran-affiliated threat actor MuddyWater (also known as Mango Sandstorm or TA450). The campaign purports to offer a genuine Remote Monitoring and Management (RMM) system called Atera.

According to Proofpoint, the operation, which ran from March 7 through the week of March 11, was directed on Israeli companies in the worldwide manufacturing, technology, and information security sectors.

According to the corporate security company, “TA450 sent emails with PDF attachments that contained malicious links.” Although TA450 is not new to this technique, the threat actor has more lately depended on inserting malicious URLs straight into email message bodies rather than taking an additional step read more Iran Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *