Tag: MuddyWater

MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack
News

MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack

In what has been called a "false flag" operation, a ransomware attack has been linked to the Iranian state-sponsored hacker outfit MuddyWater (also known as Mango Sandstorm, Seedworm, and Static Kitten). It has been discovered that the attack, which Rapid7 discovered in early 2026, uses Microsoft Teams and social engineering techniques to start the infection sequence. Evidence suggests that the outbreak is a targeted state-backed operation that poses as opportunistic extortion, despite the first appearance of the incident being compatible with a ransomware-as-a-service (RaaS) group operating under the Chaos brand. According to Rapid7's research provided with The Hacker News, the campaign was marked by a high-touch social engineering phase carried out via Microsoft Teams, where the a...
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP
News

MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

As part of a new effort codenamed Operation Olalampo, the Iranian hacker collective known as MuddyWater (also known as Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targeted a number of organizations and individuals mostly situated around the Middle East and North Africa (MENA) region. According to a Group-IB assessment, the action, which was initially noticed on January 26, 2026, has led to the deployment of new malware families that share overlapping samples that were previously detected as being used by the threat actor. CHAR is a Rust backdoor, GhostFetch drops a complex implant nicknamed GhostBackDoor, and downloaders like GhostFetch and HTTP_VIP are among them. According to the company, these attacks start with a phishing email with a Microsoft Office document attached th...
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
News

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

Using a Rust-based implant nicknamed RustyWater, the Iranian threat actor known as MuddyWater has been linked to a spear-phishing campaign that targets Middle Eastern financial, telecom, marine, and diplomatic organizations. According to a report released this week by CloudSEK resetter Prajwal Awasthi, the campaign delivers Rust-based implants with asynchronous C2, anti-analysis, registry persistence, and modular post-compromise capability augmentation using icon spoofing and malicious Word documents. The most recent development is indicative of the ongoing evolution of MuddyWater's tradecraft, which has steadily but gradually decreased its reliance on reputable remote access software as a post-exploitation tool in favor of a varied custom malware arsenal that includes tools like re...
MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign
News

MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign

A new backdoor known as UDPGangster, which employs the User Datagram Protocol (UDP) for command-and-control (C2) purposes, has been seen being used by the Iranian hacking outfit MuddyWater. According to a research from Fortinet FortiGuard Labs, users in Turkey, Israel, and Azerbaijan were the targets of the cyber espionage activities. According to security researcher Cara Lin, this malware provides remote control of compromised systems by enabling attackers to carry out commands, exfiltrate files, and deploy new payloads—all of which are conveyed using UDP channels intended to circumvent conventional network defenses. Spear-phishing techniques are used in the attack chain to disseminate Microsoft Word documents that are booby-trapped and, once macros are enabled, cause a maliciou...
Iran-Linked MuddyWater Targets 100+ Organisations in Global Espionage Campaign
News

Iran-Linked MuddyWater Targets 100+ Organisations in Global Espionage Campaign

MuddyWater, an Iranian nation-state entity, has been implicated in a recent effort that used a hacked email account to spread a backdoor dubbed Phoenix to more than 100 government agencies and other organizations around the Middle East and North Africa (MENA) area. In a technical analysis released today, Singaporean cybersecurity firm Group-IB stated that the campaign's ultimate objective is to breach high-value targets and aid in the collection of intelligence. Embassies, diplomatic missions, foreign affairs ministries, and consulates make up over three-fourths of the campaign's targets, with international organizations and telecom companies coming in second and third. According to security experts Mahmoud Zohdy and Mansour Alhmoud, MuddyWater utilized NordVPN, a legitimate prov...