MuddyWater, an Iranian nation-state entity, has been implicated in a recent effort that used a hacked email account to spread a backdoor dubbed Phoenix to more than 100 government agencies and other organizations around the Middle East and North Africa (MENA) area.
In a technical analysis released today, Singaporean cybersecurity firm Group-IB stated that the campaign’s ultimate objective is to breach high-value targets and aid in the collection of intelligence.
Embassies, diplomatic missions, foreign affairs ministries, and consulates make up over three-fourths of the campaign’s targets, with international organizations and telecom companies coming in second and third.
According to security experts Mahmoud Zohdy and Mansour Alhmoud, MuddyWater utilized NordVPN, a legitimate provider that the threat actor misused, to gain access to the infected mailbox read more about Iran-Linked MuddyWater Targets 100+ Organisations in Global Espionage Campaign.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
