MuddyWater Deploys UDPGangster Backdoor in Targeted Turkey-Israel-Azerbaijan Campaign
A new backdoor known as UDPGangster, which employs the User Datagram Protocol (UDP) for command-and-control (C2) purposes, has been seen being used by the Iranian hacking outfit MuddyWater.
According to a research from Fortinet FortiGuard Labs, users in Turkey, Israel, and Azerbaijan were the targets of the cyber espionage activities.
According to security researcher Cara Lin, this malware provides remote control of compromised systems by enabling attackers to carry out commands, exfiltrate files, and deploy new payloads—all of which are conveyed using UDP channels intended to circumvent conventional network defenses.
Spear-phishing techniques are used in the attack chain to disseminate Microsoft Word documents that are booby-trapped and, once macros are enabled, cause a maliciou...

